Several end-to-end encryption technologies for emails such as PGP and S/MIME exist since decades. However, end-to-end encryption is barely applied. To understand why users hesitate to secure their email communication and which usability issues they face with PGP, S/MIME as well as with pEp (Pretty Easy Privacy), a fairly new technology, we conducted an online survey and user testing. We found that more than 60% of e-mail users are unaware of the existence of such encryption technologies and never tried to use one. We observed that above all, users are overwhelmed with the management of public keys and struggle with the setup of encryption technology in their mail software. Even though users struggle to put email encryption into practice, we experienced roughly the same number of users being aware of the importance of email encryption. Particularly, we found that users are very concerned about identity theft, as 78% want to make sure that no other person is able to write email in their name.
翻译:PGP和S/MIME等电子邮件的端对端加密技术自几十年以来就存在了。然而,端对端加密几乎没有被应用。为了理解用户为什么犹豫不决地要保护他们的电子邮件通信,以及他们与PGP、S/MIME和PEP(Pretty Easy Pritial Pritience)的可用性问题,我们进行了在线调查和用户测试。我们发现60%以上的电子邮件用户不知道这种加密技术的存在,并且从未尝试使用。我们发现,最重要的是,用户对公共钥匙的管理感到负担过重,而且难以在邮件软件中设置加密技术。尽管用户努力将电子邮件加密付诸实践,但我们也经历了同样多的用户意识到电子邮件加密的重要性。特别是,我们发现用户非常关心身份盗窃问题,因为78%的用户想确保其他人都无法以自己的名义写电子邮件。