Oddbean new post about | logout
 If you would have to send me an encrypted email and you had no other way of communicating with me, how would you encrypt it? 
 Using your npub 
 Do you mean DM by nostr? 
 No, I mean, if I need to send you an encrypted email and there is no way we can communicate to exchange some keys, we can use your npub and encrypt the body of the email with it. This can also be done with pgp and keyservers, but the social graph and wot of nostr seems more accessible 
 Do you have your PGP keys published? 🐶🐾🫡 
 Exchange pgp keys and take it from there 
 This 
 Sounds good. But let‘s assume, I am afraid, that my OS is compromised and someone can capture my screen. How am I supposed to proceed now? 
 That wasn’t even the question. Wtf are you smoking? 
 What a nice idea, Marek: let‘s bring some twitter toxicity to nostr.
 😗 
 In this scenario, had I previously communicated with you offline / out of band? Or is it a "cold" approach?

If its a "cold" approach, and I knew your email address, I'd query PGP keyservers to see if you had a public key already out there.

If I get a reply, then its either real or else a hostile controls your email address as well. 
 Send sats with message on minibits. 
 Look for PGP key on github etc. Then use good old pgp 
 #nostr by default 
 Does it have to be encrypted with your keys? If not, encrypt with my pub key and just sned it. You won't be able to decrypt it though.  
 Nice one  
 Bwauahahhaha 
 Caesar cypher obvi 
 That depends on who "you" are, and what the purpose of the communication is. Assuming the highest level of security and If the recipient has a pgp key and I want to be assured the message is not lying around after its delivered; I would send a tor link to a one-use "burn after reading" (like from start9) message with a strong password that I provided in-person. I would also be sure the recipient is reading the message on a relatively secure computer. In addition i would assume any computer connected to the internet is compromized and the message itself should be limited such that the message is ambiguous and contains primarily references to phrases and ideas that only the two of us understand. 
 I would just shift all letters to left by 1 🤪 
 Is that rhetorical? You've made this hard for people. It's your fault.  If you at least signed commits one could encrypt to you using that key. https://github.com/callebtc.gpg

The truth is I wouldn't email you. I would move on with my life after not finding a pgp key for you easily. 
 However we encrypted things the last time we chatted.  If we've never chatted, then I'll encrypt it however we diacussed when we exchanged keys.

If we never met and never exchanged keys and I'm just assuming I have the right one...Idunno...blind PGP I guess? 
 I'm literally telling you all what my public key is right now! 
 How would you decrypt it (tools-wise)? 
 PGP, the rest is muhhh 
 That's what we have your npub for, don't we?