Existing end-to-end-encrypted (E2EE) email systems, mainly PGP, have long been evaluated in controlled lab settings. While these studies have exposed usability obstacles for the average user and offer design improvements, there exist users with an immediate need for private communication, who must cope with existing software and its limitations. We seek to understand whether individuals motivated by concrete privacy threats, such as those vulnerable to state surveillance, can overcome usability issues to adopt complex E2EE tools for long-term use. We surveyed regional activists, as surveillance of social movements is well-documented. Our study group includes individuals from 9 social movement groups in the US who had elected to participate in a workshop on using Thunderbird+Enigmail for email encryption. These workshops tool place prior to mid-2017, via a partnership with a non-profit which supports social movement groups. Six to 40 months after their PGP email encryption training, more than half of the study participants were continuing to use PGP email encryption despite intervening widespread deployment of simple E2EE messaging apps such as Signal. We study the interplay of usability with social factors such as motivation and the risks that individuals undertake through their activism. We find that while usability is an important factor, it is not enough to explain long term use. For example, we find that riskiness of one's activism is negatively correlated with long-term PGP use. This study represents the first long-term study, and the first in-the-wild study, of PGP email encryption adoption.
翻译:现有的终端到终端加密(E2EE)电子邮件系统,主要是PGP(E2EE)电子邮件系统,在受控制的实验室环境中已经进行了长期评估。虽然这些研究揭示了普通用户的可用性障碍,并提供了设计改进。虽然这些研究揭示了普通用户的可用性障碍,并且提供了设计上的改进,但有些用户迫切需要私人通信,他们必须应对现有的软件及其局限性。我们试图了解,受具体隐私威胁驱动的个人,例如易受国家监控的个人,是否能够克服使用复杂的E2EEEE系统工具的长期使用问题。我们调查了区域活动家,因为社会运动的监测是有证据的。我们的研究小组包括来自美国9个社会运动团体的个人,他们选择参加关于使用Tunebird+Enigmail进行电子邮件加密的讲习班。这些讲习班工具位于2017年中期之前,他们必须与一个非营利团体结成伙伴关系,支持社会运动团体。在他们的PGP加密培训六至四十个月后,半数以上的研究参与者继续使用PGPGE电子邮件加密,尽管首先对简单的E2G信息应用程序进行了广泛的应用。我们研究研究,但研究的相互作用性与诸如电子邮件的动机和风险是长期性研究。我们发现,一个长期使用这个研究,而长期使用这个研究的标志性研究是非性研究, 。我们发现一个长期使用。我们通过一个积极性研究,我们发现一个非常性研究, 是如何使用。我们有足够的一个长期使用。