Backwards compatibility is the killer. The whole design of PGP is to be the envelope to make email private, versus the plaintext postcard that everybody can read. It works with existing servers and existing mail clients. The biggest Snowden revelation is the importance of metadata. Just knowing whom you talk to, when, is frequently enough to compromise the parties involved. You might be doing something legal now, but…
In these discussions about the importance of metadata, I'm surprised that Bitmessage is rarely mentioned. The Bitmessage protocol is decentralized, trustless, and hides metadata such as the sender and receiver of messages.
Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
101–110 of 165 posts
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#102Backwards compatibility is the killer. The whole design of PGP is to be the envelope to make email private, versus the plaintext postcard that everybody can read. It works with existing servers and existing mail clients. The biggest Snowden revelation is the importance of metadata. Just knowing whom you talk to, when, is frequently enough to compromise the parties involved. You might be doing something legal now, but…
I can't agree with this assessment. Personally, the NSA or pervasive surveillance use case is overblown and a low risk threat to me. Anyone reasonably competent conducting the most cursory of investigations could figure out who I do business with in hours. The NSA boogeyman with omniscient network surveillance capability will come up with ways to find the source/destination of obfuscates messages anyway. Sensitive da…
EDIT: grammar
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#103Earlier quoted context omitted.
SMTP with TLS doesn't leak any metadata except the connecting IP address. And with DMARC you can mandate it. Calls for whole new protocols for email are usually made by people who don't understand the email ecosystem as it currently stands.
But SMTP with TLS is opportunistic -- and if we're talking "national state secrets" it's trivial for a state to MITM the connection and do a TLS downgrade attack.
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#104I think GPGTools for OSX does a great job of a client.
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#105Earlier quoted context omitted.
I can't agree with this assessment. Personally, the NSA or pervasive surveillance use case is overblown and a low risk threat to me. Anyone reasonably competent conducting the most cursory of investigations could figure out who I do business with in hours. The NSA boogeyman with omniscient network surveillance capability will come up with ways to find the source/destination of obfuscates messages anyway. Sensitive da…
What about the chilling effect? People change their behaviors when they know they're being watched. It goes completely against the spirit of the US Constitution. How can I pursue happiness if I'm worried that what I write will be a liability in the future? EDIT: grammar
So I choose to focus on what I can control.
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#106Earlier quoted context omitted.
What about the chilling effect? People change their behaviors when they know they're being watched. It goes completely against the spirit of the US Constitution. How can I pursue happiness if I'm worried that what I write will be a liability in the future? EDIT: grammar
I disagree with the surveillance society, but I can't control that policy. So I choose to focus on what I can control.
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#107Earlier quoted context omitted.
Correct. And now they encrypt all the inter-data center traffic. Question: Is that done on an end-to-end basis? Or do they encrypt the links between data centers? I want to encrypt a 10g ethernet and all the solutions look quite expensive. Has anyone done high speed encryption (i.e. 10gbps/1500 byte packets) with strongswan or similar?
You have to encrypt the transport at the application layer when you're talking about the scale of major internet companies--there are so many links going out of each datacenter that it's not feasible to do IPsec or similar lower level encryption. There aren't many hardware devices sold that can do the encryption at the 10-100+ Gbps speeds that datacenter links use (if any), and it's much easier to amortize the encryp…
You are vastly underestimating AES-NI. Most modern Intel CPUs can handle that kind of encryption throughput (when paired with fast enough memory). Even my old Sandy Bridge-E CPU from 2011 gives me ~96 Gbps of AES throughput (with quad channel memory).
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#108Earlier quoted context omitted.
> In practice, I heard someone say that the biggest improvement in people’s privacy has been use of Gmail. In practice, until Snowden happened, NSA was able to access all the Google's internal data as Google replicated in plaintext its whole datacenters through the links snooped by the NSA or the GCHQ. http://www.slate.com/blogs/future_tense/2013/10/30/nsa_smile...
Correct. And now they encrypt all the inter-data center traffic. Question: Is that done on an end-to-end basis? Or do they encrypt the links between data centers? I want to encrypt a 10g ethernet and all the solutions look quite expensive. Has anyone done high speed encryption (i.e. 10gbps/1500 byte packets) with strongswan or similar?
Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#109Re: Why Johnny Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client
#110Earlier quoted context omitted.
What about the chilling effect? People change their behaviors when they know they're being watched. It goes completely against the spirit of the US Constitution. How can I pursue happiness if I'm worried that what I write will be a liability in the future? EDIT: grammar
I disagree with the surveillance society, but I can't control that policy. So I choose to focus on what I can control.
The main thing that stuck out to me about your post was "low risk to me." I have studied risk extensively, and I would like to point out that generally, risks are classified with ratings of both frequency and severity. I would categorize the NSA spying as moderate-high risk (to you) due to their extremely high frequency. Yes, the severity to you will be relatively moderate (chilling effect, etc), but the cumulative, unrelenting effect it has is incredible.
As I'm thinking about this more, it's not even a true "risk," because risk always entails uncertainty. You are certainly being affected by it. The true risk of the spying program is that somehow you are hung by your own words, which has an extremely high severity (prison aka slavery). I hope that this rings true to you. Rereading what I've written, it seems like I could be projecting a lot of my own feelings and experiences onto you, but this stuff is just so universal in its effects.
Thanks for discussing this! Have a great day.