If you need to send me a confidential message, there are several ways you can safely do that.

Need to verify my digital signature? Visit the Verify Page instead.

Keybase - the simple way

Keybase is the easiest platform to make cryptography accessible to everyone. With Keybase you can encrypt and decrypt messages using open protocols.

You can use the Keybase website to encrypt a message with my key and send me the encrypted message however you want, even by email, text message, or by publicly publishing it on your Facebook wall, and only I will be able to decrypt and read its content.

DOWNSIDES (for those who care): The website is hosted on Amazon AWS and the backend is not open source.

Keybase encryption

Steps

  1. Open my Keybase encryption page
  2. Write your message
  3. Encrypt it
  4. Send me the encrypted message via email, text message, or wherever you want.

GPG - the hard way

GNU Privacy Guard is the most advanced secure communication and signature software available, and uses the PGP standard, which is what I personally trust most.

DOWNSIDES: It is very hard to use if you are not a techie.

GPG encryption

Steps

  1. Get my GPG public key from https://keybase.io/palinuro/pgp_keys.asc
  2. Install the official GPG client, or another PGP client
  3. Import my key
  4. Encrypt your message using my key as the target

Protonmail and Tutanota

If you have a Protonmail or Tutanota account, you can send me encrypted messages by using my Protonmail and Tutanota email accounts.

My accounts are:

My @palinuro.dev and @palinuro.me emails are also hosted on Protonmail (at least for now).

DOWNSIDES: It works only with Protonmail->Protonmail or Tutanota->Tutanota communications. The email protocol’s security is broken at its core, and inter-provider email exchange is NOT safe unless both sides use custom end-to-end encryption on top of it, with not-so-practical techniques as shown above.

Protonmail GPG encryption

Steps

If you have received an encrypted email from my Protonmail or Tutanota accounts, please follow the steps below.

  1. Follow the link in your email
  2. Use the password we have agreed on, or call me to get one.

Other methods

Signal

I use Signal for quick and secure confidential messages, audio and video calls.

Signal is an amazing alternative to Telegram and WhatsApp. It does encryption right and it is one of the best communication applications developed so far.

Signal supports usernames, so you can contact me without needing my phone number.

My Signal username is @palinuro.42

DOWNSIDES: You need a Signal account to contact me, and Signal still requires a phone number to sign up.

Telegram Secret Chats

I use Telegram a lot since it hosts many public communities that slowly replaced their IRC counterparts.

Telegram is fine for public conversation, but it is one of the worst pieces of software for private and confidential communication.

Anyway, it supports Secret Chats with end-to-end encryption.

DOWNSIDES: Secret chats are optional, and the whole Telegram experience is designed to push people into using the default unencrypted alternative. Moreover, Telegram decided to adopt their very own cryptographic algorithm, which is not considered a best practice in the crypto world, and its strength is not the best.