On Jan 25, 2014, at 10:05 , Robert Uomini <[email protected]> wrote:
> The encryption key is generated by the mail client and carried in the header, 
> so it does not appear anywhere in the content server; in fact, the content 
> server never had access to it.

Encryption key is carried in the header… Oh my…

Moderator, where are you when we need you?


On Jan 24, 2014, at 10:49 , Francesco L. <[email protected]> wrote:
> I have been reading all this contributes and my idea is that the best option 
> to protect my email is k9 plus apg.

I concur. This is a sound approach (used it with PGP and desktop email for 
decades).

> Having said so, I would also add that log in seems to be safe over wifi 
> networks because gmail requires ssl/tls. 

Again, I concur.

> That's the idea I'be got until now. Using servers with keys generated by 
> others doesn't seem to me the safest idea.

:-)

> I also tried Google double step verification and it is by far so complicated 
> and potentially a real pain if the account gets locked when must needed that 
> I decided not to opt for it. 

I’d disagree here: two-step verification isn’t that complicated. Its benefits 
IMHO outweigh the disadvantages by a large margin.
 

-- 
-- 
You received this message because you are subscribed to the K-9 Mail Users List.
To post to this group, send email to [email protected]
To unsubscribe, email [email protected]
To report an issue with K-9 Mail, visit 
http://code.google.com/p/k9mail/issues/list
For more options, visit this group at http://groups.google.com/group/k-9-mail

--- 
You received this message because you are subscribed to the Google Groups "K-9 
Mail" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to