Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

101–110 of 350 posts

Re: I'm giving up on PGP

#101
post #25

Earlier quoted context omitted.

This has been my experience. The only "good" experience I've had with encrypted messages through email was a back and forth exchange I had with a fellow Keybase user where I manually copy and pasted blocks of encrypted text into/out of their web interface.

From my experience - the only PGP users I've spoken to were all on Keybase or interested in a Keybase invite. It was about 6 people for the entirety of last year - and 3 people this year...it certainly has a problem of "almost nobody uses it" but Keybase seems to have eased things slightly - or at least made it easier to discover people who also use PGP. I see the two problems being "People don't bother with the clun…

I have a keybase account and don't really use it. I like the idea, but part of the issue for me is attaching my "real name" to various online identities. I've used different types of pseudonyms over the years and do to poor opsec, some of them could be linked to me using the pseudonyms I use now. It's nothing illegal, but also nothing I'd like others to know about. So to attach my real name to keybase, I'd have to reestablish my identity in various places. Doing that, of course, removes some of the trust associated with the keybase model.

Additionally, and I realize this is tangential to this discussion, I use pseudonyms to somewhat reduce my privacy "surface", so to speak. If I take my twitter, HN, reddit, etc, etc. and say "this is me", you could build a pretty decent profile of who I am (politics, hobbies, profession, where I live and so on). That's a different privacy problem than keybase is trying to solve, so no criticism is intended, but it is a problem for me.

Re: I'm giving up on PGP

#102

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

I'm going with fundamentally flawed. Or perhaps more exactly, a solution for a non-problem. Things PGP can do: - Hide the contents of a message. But not the fact of a message nor who it's to. And it's only as hidden as a key that your recipient has to keep secret indefinitely. - Permanently be incriminating, since the message can be as easily opened a decade from now. - Prove you're you. Which is great for incriminat…

1) Key rotation can solve the second part of this.

2) Key rotation solves this, but you lose the ability to read old messages yourself. If you don't have the keys anymore you can't view the message.

3) This isn't unique to PGP? Or do you have an alternative? Because plaintext is infinitely less secure in this regard.

4) Depends how you determine trust of a user. In an ideal world you'd be correct. But I trust the person I've known for nearly 6 years is them when I signed their key, though we've never met IRL. Very possible it isn't them but is also astronomically slim of a chance.

Key rotation makes the WoT even more complicated and less trustworthy. That's a big problem.

Re: I'm giving up on PGP

#103

PGP may have broken down for the author, but it's still used in a lot of places . For example, to communicate with our bankers at work, every email has to be properly encrypted and signed - or it goes into a blackhole. The only way to exchange public keys(initially) is in person. Once that is done, new keys are provided from that person, and the WoT expands. tldr; it doesn't work for the author, but it does work for…

PGP is also used very heavily on darknet on drug marketplaces.

OTR (or even Signal) is not possible there, so people stick to good-and-tried PGP.

Re: I'm giving up on PGP

#104
post #63

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. Why not both? PGP is definitely flawed with its lack of perfect forward secrecy.

Perfect forward secrecy requires interaction between the two parties. So, either you need to require both parties be online simultaneously for their first interaction, or you give up on E2E encryption, or you allow the first message to not have PFS. (After you've established two-way communication, you can use Signal's dual crypto ratchet mechanism to maintain perfect forward secrecy with offline operation.) Now, maybe that first message is the null message or just a simple low-secrecy "Hello" message, but you still need that extra initial round-trip message to establish PFS.

Of course, you need to delete emails once sent and once read in order for PFS to be of much value. However, without PFS, there's really no such thing as a deleted email, just emails the FSB/NSA haven't yet rubber-hosed you for the keys yet.

Re: I'm giving up on PGP

#105

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

I'm going with fundamentally flawed. Or perhaps more exactly, a solution for a non-problem. Things PGP can do: - Hide the contents of a message. But not the fact of a message nor who it's to. And it's only as hidden as a key that your recipient has to keep secret indefinitely. - Permanently be incriminating, since the message can be as easily opened a decade from now. - Prove you're you. Which is great for incriminat…

Add one more thing: stop the NSA per the Snowden leaks. Everything else in the leaks failed that test. Using a solution strong against the strongest attacker is worthwhile to people wondering how good various solutions really are.

Far as a decade from now, that's probably all you need given the statute of limitations.

Re: I'm giving up on PGP

#106

Dark Mail seems to be dead. Are there any efforts to make e-mail secure by default and e2e encrypted?.

Why not S/MIME? Most clients support it, its stupid easy, and has had a lot of eyes on it considering its age. Constantly re-inventing email encryption seems to be the problem here. None of them really make this stuff any better. Key distribution is still going to be PITA, but sticking with a supported standard makes the most sense.

No one seem to want to touch anything that already exists. Never heard of anyone thinking of redesigning UI/UX for a typical MUA or browser's keystore (throwing in BTBV option or whatever), although I still believe that must be possible. Everyone's off with their own proprietary non-interoperable (occasionally, "open") standards.

Also, _almost_ no client supports _any_ form of authentication and encryption on mobile, be it OpenPGP, S/MIME, PEP, SaltPack or whatever else. There are few, but that's not even remotely close to "most". Neither there is much choice of good desktop client software as well.

Re: I'm giving up on PGP

#107
People who use PGP keys, can you give examples of your use? I'm genuinely curious. Who are you contacting, or who is contacting you? The author says he only receives 2 encrypted emails a year. Not only do I not have a PGP key, I don't think I've ever found myself in a situation where it was even an option to use one.

Re: I'm giving up on PGP

#108
post #85

Earlier quoted context omitted.

"How do you distribute the one time pad " Well you hand it over to the person you want to communicate with when you see them? Obviously that doesn't work in many use cases, but in many other cases it does: many of the most important secrets are typically shared with people you already know and have met before, no?

When did you meet Paul Graham and hand over to him the crypto material you are using on the HTTPS connection you are reading this on? The vast majority of encryption in the real world is between people who did not meet and exchange crypto info. (Note this is specifically about one-time pads. While I agree the Web of Trust has failed, it is one effort to circumvent the problem.)

If he cared then he'd probably be the one handing over crypto material and instructions (about whatever crypto), as you probably need some clout to make it happen.

If even he says "write me an email in plaintext" then I'm not too hopeful for crypto in General.

Re: I'm giving up on PGP

#109

9/10 end users just don't understand that security and convenience are inversely related.

Systems like Signal and WhatsApp show that that's not necessarily true to the degree of previous solutions.

> Systems like Signal and WhatsApp show that that's not necessarily true to the degree of previous solutions.

I dunno if I'd really believe that until either company is willing to put a rising bounty starting at say $10 million USD for a real* break. Then we'll see.

*not due to user carelessness or social engineering

Re: I'm giving up on PGP

#110
post #102

Earlier quoted context omitted.

I'm going with fundamentally flawed. Or perhaps more exactly, a solution for a non-problem. Things PGP can do: - Hide the contents of a message. But not the fact of a message nor who it's to. And it's only as hidden as a key that your recipient has to keep secret indefinitely. - Permanently be incriminating, since the message can be as easily opened a decade from now. - Prove you're you. Which is great for incriminat…

1) Key rotation can solve the second part of this. 2) Key rotation solves this, but you lose the ability to read old messages yourself. If you don't have the keys anymore you can't view the message. 3) This isn't unique to PGP? Or do you have an alternative? Because plaintext is infinitely less secure in this regard. 4) Depends how you determine trust of a user. In an ideal world you'd be correct. But I trust the per…

Missing the point a little bit on 4.

Proving you're you is great if you're, say, Canonical distributing package updates to Ubuntu, where the adversary is malware distributors.

But where your adversary is eg: the FBI, then it promotes a false sense of assurance, because it's actually really easy to spoof someone if you can arrest them and force them to give the key password.

Post reply on HN