Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

41–50 of 350 posts

Re: I'm giving up on PGP

#41
post #5

After all that, he was only getting two encrypted emails a year! Damn. That's crazy.

The deepest I ever got into active PGP/GPG was in college (where it is certainly easiest to have WoT key signing parties) and so far as I recall none of us ever really bothered encrypting anything to each other, we just signed a most of our emails as something of a prideful badge that didn't really mean much all things told. (To the point where at least one friend made a joke fake PGP signature that wouldn't verify to just prove no one was bothering to verify them either.)

Re: I'm giving up on PGP

#42
post #13

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases…

> Like the author, I think the Keybase approach is a good idea. In fact I'd even suggest that the idea should be generalized away from "social media accounts" to just "potentially unreliable mechanism" in general.

It already has this to a small extent. You can sign other stuff like domain DNS entries or HTTP servers (by hosting a file).

Re: I'm giving up on PGP

#43
post #26
post #14

I've been thinking a lot about PGP and other encrypted messengers lately. It's incredibly hard to get a lot of people to agree on one messaging app besides default SMS. I wish there was an open source suite of tools for mobile/desktop that easily layered PGP on top of SMS/email experience and would fall back in the absence of keys. Perhaps bluetooth for swapping keys with friends. It's something that needs to be seam…

Carriers would need to change the way they handle SMS, and everything a carrier does is subject to state regulations. And states seem to like clear text.

Why's that? I understand the message would increase in size because of the encryption, but I think it would be technically feasible now. Didn't even apple just introduce encryption into their messenger? My issue with apple's encryption is it's closed source and apple only.

Re: I'm giving up on PGP

#44

Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.

https://pep.foundation/

Commercial offerings for companies at https://www.prettyeasyprivacy.com/

(No, they are not, as far as I know “open core” – they are 100% free software.)

Re: I'm giving up on PGP

#45
post #8

Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.

Most interesting e2e projects have abandoned email, specifically SMTP, as a secure messaging platform. I would look outside SMTP-based solutions if I were to start using a different project (assuming doing so is an option... I hope it is!). My recommendation here is Signal: https://whispersystems.org/

Signal is nice, and I use it. But it's an instant messaging system. Email has different use cases.

I think what we're going to need is a new, non-SMTP protocol, which preserves all of the good things about email, while providing e2e encryption and (pseudonymous) identity assurance. I don't know enough to be involved in designing that protocol, though, other than saying what I want to see as an end-user.

Re: I'm giving up on PGP

#46

To me, Keybase ( https://keybase.io ) seems to solve the "PGP has a bad user experience" problem correctly for like 90% of the population. You post proofs of your public key to known media (Twitter, Github, your website, etc.) which you control. These can be checked by anyone. Even if the remote person doesn't know they are talking to you (as a human entity), they know they are talking to the combined online persona…

Is keybase open source?

I believe a lot/all of their stuff is, github repos here https://github.com/keybase

Re: I'm giving up on PGP

#47

To me, Keybase ( https://keybase.io ) seems to solve the "PGP has a bad user experience" problem correctly for like 90% of the population. You post proofs of your public key to known media (Twitter, Github, your website, etc.) which you control. These can be checked by anyone. Even if the remote person doesn't know they are talking to you (as a human entity), they know they are talking to the combined online persona…

For me keybase solves a lot of the WoT problem but not the day-to-day usuability problem.

The killer is lack of good x-platform e-mail integration + difficulties in key management.

I was hoping keybase might take that on as well, but AFAIK that's not on their roadmap.

Re: I'm giving up on PGP

#48
There isn't a lot to unpack in this article. Most is set-up; explaining how connected he is to a community that is enthusiastic about PGP yet doesn't apply secure operations in practice.

Then there is the main complaint:

> I haven't done a formal study, but I'm almost positive that everyone that used PGP to contact me has or would have done (if asked) one of the following:

> - pulled the best-looking key from a keyserver, most likely not even over TLS

> - used a different key if replied with "this is my new key"

> - resent the email unencrypted if provided an excuse like "I'm traveling"

I haven't done a formal study either, but no one I know that uses PGP would do any of these things under any circumstances. PGP works fine for myself and the group of people I know that use it, because we adhere to security protocols that are just as important -- if not more -- than using PGP itself.

Re: I'm giving up on PGP

#49

9/10 end users just don't understand that security and convenience are inversely related.

I think they understand that quite well, that's why when security gets in the way they just find a way bypass it.

Security has to be usable, if it's not usable then (almost) no one will use it.

Re: I'm giving up on PGP

#50
post #13

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases…

[deleted]
Post reply on HN