Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

81–90 of 350 posts

Re: I'm giving up on PGP

#81

On a related thought, using a 'secure' (or so they say ?) email provider à là protonmail is just secure if you send your email to another protonmail user. Problem with services like that is they omit to tell their users that email is not E2E, and sending from protonmail to gmail will just disable the benefits of using protonmail. So yes, if you are trying to send encrypted email to a GMAIL user, your only way is to u…

I don't want to be a defender of snake-oil email providers but I think a 'secure' e-mail provider hopefully does more then just GPG to other users.

They hopefully have a good secure authentication system (Protonmail just added SRP and 2Fa) and hopefully have correct policy for things such as DKIM, SPF.

They hopefully also keep up with security updates and stuff like that.

Doing these things seems normal to many, but the reality is that many E-Mail providers have non of those things.

Re: I'm giving up on PGP

#82

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here.

Last time I tried to use PGP on Windows, the gpg4win setup application crashed repeatedly during installation, and I had to use a walkthrough with screenshots because I couldn't figure out how to sign messages in Thunderbird.

Forget deep conceptual usability issues; there are tons of major surface level usability issues.

Re: I'm giving up on PGP

#83

Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.

A few projects that I'm aware of (disclaimer: I'm involved with LEAP): - https://pixelated-project.org/ - https://www.mailpile.is/ - https://modernpgp.org/memoryhole/ - https://inbome.readthedocs.io/en/latest/ - https://leap.se/ Edit: btw, if you're in Berlin from 14-18 Dec, drop by the AME2016 unconf+hackaton https://github.com/mailencrypt/ame2016

Hah: http://i.imgur.com/YphQVru.png

Re: I'm giving up on PGP

#84
post #13

Earlier quoted context omitted.

"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases…

"How do you distribute the one time pad " Well you hand it over to the person you want to communicate with when you see them? Obviously that doesn't work in many use cases, but in many other cases it does: many of the most important secrets are typically shared with people you already know and have met before, no?

That's exactly what the OP was talking about when s/he said "temporally shift your security".

Re: I'm giving up on PGP

#85
post #13

Earlier quoted context omitted.

"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases…

"How do you distribute the one time pad " Well you hand it over to the person you want to communicate with when you see them? Obviously that doesn't work in many use cases, but in many other cases it does: many of the most important secrets are typically shared with people you already know and have met before, no?

When did you meet Paul Graham and hand over to him the crypto material you are using on the HTTPS connection you are reading this on?

The vast majority of encryption in the real world is between people who did not meet and exchange crypto info.

(Note this is specifically about one-time pads. While I agree the Web of Trust has failed, it is one effort to circumvent the problem.)

Re: I'm giving up on PGP

#86
post #71

Earlier quoted context omitted.

Signal is nice, and I use it. But it's an instant messaging system. Email has different use cases. I think what we're going to need is a new, non-SMTP protocol, which preserves all of the good things about email, while providing e2e encryption and (pseudonymous) identity assurance. I don't know enough to be involved in designing that protocol, though, other than saying what I want to see as an end-user.

What properties does email have that asynchronous messaging services (e.g. Signal) do not?

Cross-platform (Chrome web-apps don't count), Federated, Distributed, to name a few. The reason email is so entrenched is probably because of these reasons entirely. Being able to send a message from any provider to any provider certainly helped spread adoption easily.

Re: I'm giving up on PGP

#87
post #32

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

Yeah. It takes some reading to understand the different levels of trust for a key. Even rewording those levels could be effective, if perhaps a bit verbose.

[]Distrust []Trust only this key []Trust this key to automatically trust other keys []This is my key

Obviously I dont know what all the levels exactly mean. but as far as I can tell, these are the levels of "web of trust", where for it to truly be a web, #3 should be the default.

I either dont trust someone, I trust someone to represent themselves, I trust someone's to vouch for of others, or I am that someone.

Re: I'm giving up on PGP

#88
I feel the pain as well. I'm not ready to make the same jump however.

I really do support Keybase, there I see the potential to solve many of the issues. I would love some better integration into the E-Mail ecosystem, but sadly its not there jet, and its not there focus.

Re: I'm giving up on PGP

#89
post #43
post #26

Earlier quoted context omitted.

Carriers would need to change the way they handle SMS, and everything a carrier does is subject to state regulations. And states seem to like clear text.

Why's that? I understand the message would increase in size because of the encryption, but I think it would be technically feasible now. Didn't even apple just introduce encryption into their messenger? My issue with apple's encryption is it's closed source and apple only.

Apple's iMessage just detects when the other party is using an iOS device and sends them an iMessage instead of an SMS. The GP is right; cell service is so aggressively regulated that there's no hope of carriers adopting a better standard, so the best we can hope for is that at some point mobile OS distributors agree on some open standard like the Signal protocol.

Re: I'm giving up on PGP

#90
post #73

Earlier quoted context omitted.

That is definitely not my main complaint, and I suspect it might have caught your eye because it's the one that wouldn't apply to you (which is absolutely possible). The article is about the flaws of long-term identity keys, and it would stand even if there weren't UX, adoption, or security protocols adherence issues. Maybe try to unpack a bit more :)

You're right, long-term identity keys are bad. Long-term identity keys are not a concept mandated by PGP, they are a result of how people use PGP or how PGP is implemented in a third party app. No part of PGP requires you to use a key more than once. This phenomenon is a result of a consensus of people deciding on a terrible operations strategy over a long period of time. Edit: this comes to mind https://gist.github.…

Agreed, I link to that Gist exactly in the "Moving Forward" section ;)
Post reply on HN