Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

21–30 of 350 posts

Re: I'm giving up on PGP

#22

To me, Keybase ( https://keybase.io ) seems to solve the "PGP has a bad user experience" problem correctly for like 90% of the population. You post proofs of your public key to known media (Twitter, Github, your website, etc.) which you control. These can be checked by anyone. Even if the remote person doesn't know they are talking to you (as a human entity), they know they are talking to the combined online persona…

The combined online persona of those accounts is only as strong as their combined security. aka: Why would services need to collude when they can get the job done by ineptitude?

https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...

Re: I'm giving up on PGP

#23

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

It is interesting this realization that Power Users have very similar User Experience problems in Key Management that Novice Users have, but of a different degree. It does maybe speak to a deep conceptual usability issue in the WoT model. Maybe the tough learning curve has always been a symptom of the thousand papercuts of the Knowledgeable/Power User case and it is time to question the model and look for alternatives.

The Web of Trust is built on long term trust of objects that should be short term and plentiful and that does seem an inherent contradiction in terms. WoT "best practices" have always been that keys should never live that long (at most two to five years being an old received wisdom back when I was most actively exploring the WoT), but proper key signing involves lots of little contacts (or key signing "parties") that are slow to accumulate and should last a great deal of time, but are applied to a specific key.

Power Users can get some continuity between keys when rotating them by signing new keys with old ones before they expire, if they can manage that key that long and are prescient enough to build and sign a new key. (I know I lost continuity with my most trusted WoT key by not managing it well enough and I'm certainly not alone there; there is a great deal of churn in the WoT and lot of it is expired.)

So Power Users try for longer term keys with further risks and even larger key management issues and with those longer term keys they try to manage a coterie of smaller term keys exponentially increasing the number of key management issues.

Keybase seems to be the best bet at a trust model that distinguishes active keys from long term trust (social trust), and might be a good answer if they solve "average user" user experience.

Signal and WhatsApp and some of the other OTR-ish mobile apps with E2E encryption seem to have solved some of the "average user" user experience problems, but don't seem to have good long term trust models.

Somewhere in the soup maybe someone will solve more of the chicken-and-egg hurdles and evolve something that works for everyone.

Re: I'm giving up on PGP

#24

Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.

A few projects that I'm aware of (disclaimer: I'm involved with LEAP): - https://pixelated-project.org/ - https://www.mailpile.is/ - https://modernpgp.org/memoryhole/ - https://inbome.readthedocs.io/en/latest/ - https://leap.se/ Edit: btw, if you're in Berlin from 14-18 Dec, drop by the AME2016 unconf+hackaton https://github.com/mailencrypt/ame2016

That's a very nice list of links and overlaps with some idea I had, thanks a lot !

INBOME in particular looks to me to be (part of) the way forward, is there any way to follow progress ?

Re: I'm giving up on PGP

#25
post #5

After all that, he was only getting two encrypted emails a year! Damn. That's crazy.

This has been my experience. The only "good" experience I've had with encrypted messages through email was a back and forth exchange I had with a fellow Keybase user where I manually copy and pasted blocks of encrypted text into/out of their web interface.

From my experience - the only PGP users I've spoken to were all on Keybase or interested in a Keybase invite. It was about 6 people for the entirety of last year - and 3 people this year...it certainly has a problem of "almost nobody uses it" but Keybase seems to have eased things slightly - or at least made it easier to discover people who also use PGP.

I see the two problems being "People don't bother with the clunkiness of using PGP when sending an email about what to pick up from the store" and "most users have no reason to talk to most other users".

I'm considering making it a point to message people with interesting Keybase avatars or social profiles tied to their Keybase if only to have an excuse to use PGP more, as silly as that might sound.

Re: I'm giving up on PGP

#26
post #14

I've been thinking a lot about PGP and other encrypted messengers lately. It's incredibly hard to get a lot of people to agree on one messaging app besides default SMS. I wish there was an open source suite of tools for mobile/desktop that easily layered PGP on top of SMS/email experience and would fall back in the absence of keys. Perhaps bluetooth for swapping keys with friends. It's something that needs to be seam…

Carriers would need to change the way they handle SMS, and everything a carrier does is subject to state regulations. And states seem to like clear text.

Re: I'm giving up on PGP

#27
post #5

After all that, he was only getting two encrypted emails a year! Damn. That's crazy.

Yes, surely that plays into his decision a bit. Some of us get get that every few hours from people are significant risk who really need to use PGP.

Re: I'm giving up on PGP

#28

Usability is the "key" - it's hard enough to get people to use signal ("why do I need another messaging app?")

If they don't have Signal you could get them to either use Whatsapp, or only use the encrypted conversation feature of Facebook's Messenger.

They should have one or the other already installed if they're complaining about "another messaging app".

Re: I'm giving up on PGP

#29
post #16

Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.

Google's End-To-End also seems dead. https://github.com/google/end-to-end I would say ProtonMail or the miniLock-based Peerio.com are now the most interesting projects for encrypted email. EDIT: https://minilock.io/ https://github.com/PeerioTechnologies/peerio-client

not dead [https://github.com/google/end-to-end/issues/391]

Re: I'm giving up on PGP

#30

Good points, but also I would like to point out that https://www.usenix.org/system/files/1401_08-12_mickens.pdf linked from the blog post was an entertaining read so for anyone that didn't read said PDF, do.

There's quite a few Mickens rants, and they're all well written.

Edit: Link http://mickens.seas.harvard.edu/wisdom-james-mickens

Post reply on HN