Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

141–150 of 350 posts

Re: I'm giving up on PGP

#141
post #117
post #13

Earlier quoted context omitted.

"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases…

Innovative new ways of distributing PGP key fingerprints are to be welcomed. But why would you not keep using PGP for the part that it's good at?

The author did include the standard UX-of-PGP-sucks arguments, but he was also making the point that some of the core models around PGP suck.

eg he was saying you can't share a key across multiple devices. Or if you do, you just increase your attack vector and your weakest link becomes the hotel wifi you plug into.

eg if your key does get compromised, now you have to rotate all your contacts, which if you distributed your key on a business card, is pretty friction-prone and encourages you to discount that weird activity that could have been a blip you saw on the hotel wifi.

The big one is if your key ever does get compromised, now all your past history becomes accessible. So he's saying there's some things that PGP is fundamentally bad at, and you need a new model, not just a band-aid UX fix.

> Finally, these days I think I care much more about forward secrecy, deniability and ephemerality than I do about iron clad trust. Are you sure you can protect that long-term key forever? Because when an attacker decides to target you and succeeds, it won't have access from that point forwards, but to all your past communications, too. And that's ever more relevant.

Re: I'm giving up on PGP

#142

Earlier quoted context omitted.

Why not S/MIME? Most clients support it, its stupid easy, and has had a lot of eyes on it considering its age. Constantly re-inventing email encryption seems to be the problem here. None of them really make this stuff any better. Key distribution is still going to be PITA, but sticking with a supported standard makes the most sense.

No one seem to want to touch anything that already exists. Never heard of anyone thinking of redesigning UI/UX for a typical MUA or browser's keystore (throwing in BTBV option or whatever), although I still believe that must be possible. Everyone's off with their own proprietary non-interoperable (occasionally, "open") standards. Also, _almost_ no client supports _any_ form of authentication and encryption on mobile,…

> authentication and encryption on mobile

The iOS built-in Mail application supports S/MIME. However, it doesn't support anything above TLS 1.0 for IMAP, curiously.

K-9 and the Android mail client don't support S/MIME, however.

On the desktop, Thunderbird and Outlook support S/MIME. So does mutt.

Re: I'm giving up on PGP

#143
post #124

"Yubikeys would get exposed to hotel rooms." Can someone please elaborate on this?

I took that to mean he left it in a hotel room while going somewhere, exposing it to any number of maids, possibly including those of a malevolent nature.

Re: I'm giving up on PGP

#144

On a related thought, using a 'secure' (or so they say ?) email provider à là protonmail is just secure if you send your email to another protonmail user. Problem with services like that is they omit to tell their users that email is not E2E, and sending from protonmail to gmail will just disable the benefits of using protonmail. So yes, if you are trying to send encrypted email to a GMAIL user, your only way is to u…

From what I remember, Protonmail is more about protecting the client and contents of the inbox from snooping than protecting the email content in transit between their servers and other people's clients. Supposedly, they use in-browser encryption to encrypt traffic between the browser and webmail server, and encrypt the mailbox so access to the server won't provide easy access to your account's contents. They also claim that hosting in Switzerland reduces the risk of server-side government interference.

Re: I'm giving up on PGP

#145
post #120

Earlier quoted context omitted.

I admit my ignorance of saltpack and keybase's implementation of it, but don't they propose storing the key for you? That seems to create a trust issue, which is precisely what the author is complaining people don't pay attention to, trust. On the other hand, perhaps the argument for this would be a "trusted 3rd party" model (a la S/MIME).

Well, you can have your GPG Private Key online if you like, but thats not my point. The new system moves away from having any sort of master key. Rather every device has a new key, and they all sign each other. You can add new devices without old proves being invalidated. See: https://keybase.io/blog/keybase-new-key-model and https://saltpack.org/ I would really like a solution using this stuff that is highly integra…

That's an interesting solution. Rather than having keybase keep your key, your devices are communicating directly to validate each other? I'm going to have to review this in more detail, thanks.

Re: I'm giving up on PGP

#146
post #28

Earlier quoted context omitted.

If they don't have Signal you could get them to either use Whatsapp, or only use the encrypted conversation feature of Facebook's Messenger. They should have one or the other already installed if they're complaining about "another messaging app".

This works fine until you get someone who only uses iMessage, and you use Android.

Exactly what finally convinced me to add whatsapp.

Re: I'm giving up on PGP

#147

The conclusions here (avoiding long-lived per-identity keys and having the option to easily rotate and re-validate per-device keys) are very much what we've aimed for in the end-to-end crypto for Matrix.org ( https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-en... ). Rather than using a silo like Signal or WhatsApp, it is possible to get the flexibility of an open federated network built on an open standard,…

When I mention Matrix, a lot of people seem to pigeonhole it as a chat system alone because Riot is such a dominating part of the application ecosystem. It would be really great to have more code and demonstrations available; adding Matrix was suggested for Mastodon[0] to potentially gain chat and private messaging features that aren't part of GNUSocial, but as of right now it's considered out of scope. [0] https://g…

Hum, just found the bug at https://github.com/Gargron/mastodon/issues/311 - shame that folks there haven't grokked what Matrix is. Yes, pigeonholing it as a chat system is kinda missing the point, but it's an easy way to kick the tyres and prove its potential.

Once threading lands in Matrix we'll be adding in gateways for SMTP, IMAP, NNTP, Discourse, and possibly Gnusocial etc - either written by us or from the community. Then hopefully the bigger picture will be more obvious(!)

Re: I'm giving up on PGP

#148

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

>we have a deep conceptual usability issue here.

yes, yes we do. All this stuff seems easy if you have the curiosity so spend hours and hours reading dry documentation about how it works. This is to say nothing of actually getting your hands on the tech and inevitably having problems that require more hours of forum searchs, IRC, and other time drains.

It's not that "regular" people are too stupid to do this, they just don't see the value proposition in it. Even when the privacy issue starts to negatively affect regular people (think Black Mirror "Nose Dive") many still won't be interested in the technology to do what I wrote about above.

I spent a bit of time in the crypto community and immediately I realized there is a human resources problem. the communities, for the most part, have no one that understands or care about how to dumb the UX down enough to make the value prop work for regular people.

Re: I'm giving up on PGP

#149
post #32

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

Some time ago I had an idea for a web presentation of WoT - I thought it would be fun to explore and also maybe present a kind of gamified incentive to build WoT. I also thought that given how old the thing is there should be good libraries that would make writing it easy. Unfortunately this is was not the case - there are no real libs - there are only some workarounds that shell out the execs to do the work and then parse the output and it would be to resource expensive to run it at a web server.

I don't think WoT or PGP are fundamentally flawed - but we need a lot of experimentation to make it work and for that we need good libs.

Re: I'm giving up on PGP

#150
post #143
post #124

"Yubikeys would get exposed to hotel rooms." Can someone please elaborate on this?

I took that to mean he left it in a hotel room while going somewhere, exposing it to any number of maids, possibly including those of a malevolent nature.

As far as I understand, it is not possible to extract a private key from a Yubikey [1]

[1] https://www.yubico.com/2012/12/yubikey-neo-openpgp/

Post reply on HN