What do you think?


PGP & GPG: Email for the Practical Paranoid
OpenPGP is the most widely used email encryption standard in the world. It is based on PGP (Pretty Good Privacy) as originally developed by Phil Zimmermann. The OpenPGP protocol defines standard formats for encrypted messages, signatures, and certificates for exchanging public keys. PGP & GPG is an easy-to read, informal tutorial for implementing electronic privacy on the cheap using the standard tools of the email privacy field - commercial PGP and non-commercial GnuPG (GPG). The book shows how to integrate these OpenPGP implementations into the most common email clients and how to use PGP and GPG in daily email correspondence to both send and receive encrypted email. The PGP & GPG book is written for the moderately skilled computer user who is unfamiliar with public key cryptography but who is nevertheless interested in guarding their email privacy. Lucas's trademark informal and relaxed tone makes public key cryptography as simple and clear as possible, so that any reasonably savvy computer user can understand it.
216 pages, Paperback
First published April 1, 2006
About the author
Michael W. Lucas
48 books79 followersMichael W. Lucas is the author of fifty-odd critically-acclaimed nonfiction books. As Michael Warren Lucas, he's written several novels.
Ratings & Reviews
Friends & Following
Create a free account to discover what your friends think of this book!
Community Reviews
Displaying 1 - 12 of 12 reviews
February 15, 2021
15 years is all it took for this book to go from pretty good to mostly useless. When this book was published you had to wonder if the subject matter really required an entire book. At the time it looked as though all the consumer software tools were in place and all that was needed was a little more information available in the public mainstream and encrypted email would become more widely used, perhaps even required. Well, that obviously did not occur. Even after the revelation that the US government was monitoring everyone's emails and text messages the average Joe didn't seem to care. Because of a general apathy towards digital privacy these kinds of tools are still unknown by most people who use email everyday.
If I wanted to get a friend or colleague setup with an OpenPGP encryption solution I could not recommend this book for the simple reason that the book is no longer being published, and you can't buy it. The second reason is the information in the books is too out of date, so it's good that nobody is selling it. If you generated your keys using this book you would be doing yourself a disservice. The PGP Corporation does not exist any more. Almost every URL in the book no longer exists. Encryption algorithms have changed. This book doesn't even mention the concept of subkeys. On top of all the outdated information, there is simply too much of it in the book. It would be one thing if the book discussed best practices, but that topic rarely comes up, and instead ends up being more of a long HOWTO.
So what is a paranoid person supposed to do now? You really don't need a book. If you need to learn GPG there are several good blog posts out there now that cover all the important OpenPGP use cases. Or simply type 'man gpg' at the command prompt (if you use Linux), because that still works.
If I wanted to get a friend or colleague setup with an OpenPGP encryption solution I could not recommend this book for the simple reason that the book is no longer being published, and you can't buy it. The second reason is the information in the books is too out of date, so it's good that nobody is selling it. If you generated your keys using this book you would be doing yourself a disservice. The PGP Corporation does not exist any more. Almost every URL in the book no longer exists. Encryption algorithms have changed. This book doesn't even mention the concept of subkeys. On top of all the outdated information, there is simply too much of it in the book. It would be one thing if the book discussed best practices, but that topic rarely comes up, and instead ends up being more of a long HOWTO.
So what is a paranoid person supposed to do now? You really don't need a book. If you need to learn GPG there are several good blog posts out there now that cover all the important OpenPGP use cases. Or simply type 'man gpg' at the command prompt (if you use Linux), because that still works.
December 24, 2018
If you want to learn about secure end-to-end emails, this book is wonderful.
PGP and GPG is important for one reason: secure email communications. The majority is operating with at most secure connections (TLS) which most are familiar with it as HTTPS or the lock next to the URL. However, this only provides security between you (the client) and your mail server (let's assume gmail.com). Do you trust your email provider and the security on it's subsequent network routing?
It explains security terminology, implementation steps and setup instructions. The 2 core security functionalities are Certificates and Encryption. The standards hopes to achieve Identity through Confidentiality, Integrity, Authentication/Non-repudiation. The book is assessible to non-techies yet educational to techies. A great book for anyone interseted in email security beyound TLS.
A small section on cryptography laws around the world also primes the reader to learn more about them.
PGP and GPG is important for one reason: secure email communications. The majority is operating with at most secure connections (TLS) which most are familiar with it as HTTPS or the lock next to the URL. However, this only provides security between you (the client) and your mail server (let's assume gmail.com). Do you trust your email provider and the security on it's subsequent network routing?
It explains security terminology, implementation steps and setup instructions. The 2 core security functionalities are Certificates and Encryption. The standards hopes to achieve Identity through Confidentiality, Integrity, Authentication/Non-repudiation. The book is assessible to non-techies yet educational to techies. A great book for anyone interseted in email security beyound TLS.
A small section on cryptography laws around the world also primes the reader to learn more about them.
May 7, 2023
Malgrado il titolo non è proprio un manuale pratico, ci sono alcuni esempi ma essendo che l'autore ha la pretesa di coprire 3 o 4 software diversi ha dovuto per forza tagliare sut tutto oltre che si perde molto in discorsi assai inutili.. poco consigliato. Ma essendo che libri in italiano su questo argomento si contano sulle dita di una mano do almeno 3 stelle.. per la vaga introduzione pratica a GPG.
November 20, 2017
It's an OK introduction to PGP and GPG. Easy to read. I thought the author repeated himself too many times, but that could be for the benefit of new users. Topics that that I would have liked to seen more of include GPG subkey management and multi-user signing best practices. All that being said, I will still make this recommended reading for my students.
July 10, 2018
Obviously showing its age in terms of discussion of software components, but the book remains a great resource for understanding the concepts behind encryption & use cases. Still highly recommend this book because of the things it continues to do well, despite its age.
December 10, 2012
Ever since working with OpenPGP, I instantly fell in love with it and helped spread the word around whenever I could for people who wanted a more secure method of communication via email. Just recently, a friend wanted to learn more about this awesome email encryption technology and wanted to know where to actually begin his journey. I was looking over at some books on Amazon and decided to go with PGP & GPG: Email for the practical Paranoid by Michael Lucas. It had good reviews and the book was only a little over 200 pages so it’s not too overwhelming. After borrowing the book and reading it for myself, I can definitely say that it can help someone a whole lot to begin realizing the benefits of utilizing OpenPGP for secure email communications. It won’t make you an expert by any means but I don’t think most users care. If you’re already an expert, I don’t think you should be reading this book anyways because its all about the basics here. if you have no idea on what OpenPGP is, then go ahead and do a little research online first. If you are then interested, come back and pick this book up.
What the author does here is give you a taste of what OpenPGP can do for you as far as email communications is concerned. He explains the essentials such as confidentiality, authenticity and non-repudiation and most important of all, what public and private keys are in an asymmetric encryption scheme. The author does a good job in explaining things without really over complicating it. The good news with OpenPGP is that once you grasp the basic concepts of how it works, the rest becomes fairly easy to catch on. The author goes into great detail about The Web of Trust and how key signing works. This is the area where it might scare potential users away. However, while embedding yourself into The Web of Trust system can be beneficial to you and the overall OpenPGP scheme, it is absolutely not necessary at all if all you want to do is trade secure emails between known party members. If you are going to invest heavily in OpenPGP, then yes, you should learn all you can about The Web of Trust, especially if you will be trading secure emails with people you have never met before.
In the book, the author gives example of how to use OpenPGP with a couple of products. First is Symantec’s own PGP Desktop software. The basics to get the software up and running is included such as generating you own key pair, importing and exporting your key pair, signing other public key’s and generating a revocation certificate. Second, the author explains how to install and use OpenPGP in both Windows and a Linux environment via the command line for the latter. He chooses to show how to get things up and running with the popular Mozilla Thunderbird email client with the Enigmail plugin. Configuration wise, not much else is mentioned.
Like I mentioned earlier, this book won’t make you an expert with OpenPGP. What it will help in is getting users up to date with all the terminologies and concept behind the technology so that other users such as myself can have a meaningful discussion with them without getting the deer in the headlight response! As a strong believer in OpenPGP and email encryption in general, this book is fantastic for me to recommend to people who want more information on the subject but not caring for the “mathematics” part of it.
What the author does here is give you a taste of what OpenPGP can do for you as far as email communications is concerned. He explains the essentials such as confidentiality, authenticity and non-repudiation and most important of all, what public and private keys are in an asymmetric encryption scheme. The author does a good job in explaining things without really over complicating it. The good news with OpenPGP is that once you grasp the basic concepts of how it works, the rest becomes fairly easy to catch on. The author goes into great detail about The Web of Trust and how key signing works. This is the area where it might scare potential users away. However, while embedding yourself into The Web of Trust system can be beneficial to you and the overall OpenPGP scheme, it is absolutely not necessary at all if all you want to do is trade secure emails between known party members. If you are going to invest heavily in OpenPGP, then yes, you should learn all you can about The Web of Trust, especially if you will be trading secure emails with people you have never met before.
In the book, the author gives example of how to use OpenPGP with a couple of products. First is Symantec’s own PGP Desktop software. The basics to get the software up and running is included such as generating you own key pair, importing and exporting your key pair, signing other public key’s and generating a revocation certificate. Second, the author explains how to install and use OpenPGP in both Windows and a Linux environment via the command line for the latter. He chooses to show how to get things up and running with the popular Mozilla Thunderbird email client with the Enigmail plugin. Configuration wise, not much else is mentioned.
Like I mentioned earlier, this book won’t make you an expert with OpenPGP. What it will help in is getting users up to date with all the terminologies and concept behind the technology so that other users such as myself can have a meaningful discussion with them without getting the deer in the headlight response! As a strong believer in OpenPGP and email encryption in general, this book is fantastic for me to recommend to people who want more information on the subject but not caring for the “mathematics” part of it.
February 4, 2009
When Michael Lucas' PGP & GPG: E-Mail for the Practical Paranoid was published in 2006, I was excited. The use of cryptography, once extremely common among nerds, saw an inexplicable decline after the turn of the millennium. These days even the most technically literate of my friends don't use it, not only because they don't see the purpose, but also because there are few decent web resources for all the theory around public and private keys. I hoped Lucas' book would help restore interest in cryptography.
The first two chapters introduce the concepts behind encryption. The book comes from No Starch Press, so the intended audience is a technical one, comfortable with reading such a fairly rigorous computing manual. His book does not take care of the need for a more general introduction to encryption. And he assumes that if you've bought the book, you've already decided that you need encryption. I thought it would have been nice if he had talked about why encryption of communications is important, for example by citing the old adage that encryption is just an envelope over the postcard that is e-mail. The book is also for an American audience. I get most of Lucas' obscure jokes and cultural references, but for English-speaking readers from other countries the tone of Lucas' writing must be somewhat irritating.
In instructing the reader how to actually use cryptography in daily life, Lucas describes two implementations of the OpenPGP standard. The first is PGP, the proprietary program that costs money, is controlled by a single corporation, and whose source code is not publicly available, but which Lucas feels is best for those with limited computing skills and a need for technical support. The second program is GnuPG, the Free Software tool that is freely available and whose source code can be audited by anyone, but which might be challenging to use for some. He does talk about the WinPT graphical interface for GnuPG on Windows, but it's a pity that he doesn't describe Linux key management interfaces like Seahorse. As the subtitle promises, Lucas does a good job of showing you how to work encryption into common e-mail clients like Outlook and Thunderbird.
Lucas tries hard to encourage good cryptographic practice. The final chapter talks about the limitations of encryption in the face of poor keysigning, or software or hardware compromise (but where's the mention of TEMPEST?).
If you're a technical person who is committed to implementing encrypted e-mail in your personal life or small company, Lucas' guide is a decent read.
The first two chapters introduce the concepts behind encryption. The book comes from No Starch Press, so the intended audience is a technical one, comfortable with reading such a fairly rigorous computing manual. His book does not take care of the need for a more general introduction to encryption. And he assumes that if you've bought the book, you've already decided that you need encryption. I thought it would have been nice if he had talked about why encryption of communications is important, for example by citing the old adage that encryption is just an envelope over the postcard that is e-mail. The book is also for an American audience. I get most of Lucas' obscure jokes and cultural references, but for English-speaking readers from other countries the tone of Lucas' writing must be somewhat irritating.
In instructing the reader how to actually use cryptography in daily life, Lucas describes two implementations of the OpenPGP standard. The first is PGP, the proprietary program that costs money, is controlled by a single corporation, and whose source code is not publicly available, but which Lucas feels is best for those with limited computing skills and a need for technical support. The second program is GnuPG, the Free Software tool that is freely available and whose source code can be audited by anyone, but which might be challenging to use for some. He does talk about the WinPT graphical interface for GnuPG on Windows, but it's a pity that he doesn't describe Linux key management interfaces like Seahorse. As the subtitle promises, Lucas does a good job of showing you how to work encryption into common e-mail clients like Outlook and Thunderbird.
Lucas tries hard to encourage good cryptographic practice. The final chapter talks about the limitations of encryption in the face of poor keysigning, or software or hardware compromise (but where's the mention of TEMPEST?).
If you're a technical person who is committed to implementing encrypted e-mail in your personal life or small company, Lucas' guide is a decent read.
February 21, 2017
Really great content! It's definitely showing it's age at this point (copyright 2006) but you can fill in the gaps pretty well by following the information provided here. Screenshots are outdated and the applications are different but the functionality is the same.
September 28, 2013
As someone who is quite interested in computer security I have been using GPG for a couple of years already. Due to the current stream of revelations around the NSA and its means of basically intercepting everything, I wanted something I can recommend to my friends when talking about how to protect their privacy and keep the content of mails confidential. I guess the book is good enough for someone, who is only looking for that. After reading the book you probably should be able to use the encryption software on a day to day basis and know at least something about the topic. But that's about it. I think that a lot of essential (cryptographical) background was left untouched and/or was not explained thoroughly enough. Even quite important concepts like the use of "hybrid ciphers" was neither mentioned nor linked to OpenPGP. So you most certainly won't get an expert and will have to go through various other resources to get a real understanding of what is actually going on underneath. Nevertheless I would recommend this to everyone interested in starting to use OpenPGP.
October 12, 2016
Very useful and easy to follow along with, although the book is showing it's age a little and is in need of an update. Yes, while a lot of the information floating around in the book is available for free on the internet, it's very useful to have a book like this that consolidates and focuses on the main principles of GPG and OpenPGP.
August 11, 2016
GPG (PGP) was something I've been tinkering with (or at least wanted to tinker with) recently, but without much knowledge. This was a great introduction, and has definitely made me see things more clearly and where most of them fit together. Would recommend, definitely.
July 24, 2015
Awesome intro to PGP and GnuPG.
Displaying 1 - 12 of 12 reviews










