Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

231–240 of 350 posts

Re: I'm giving up on PGP

#231
post #32

Earlier quoted context omitted.

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

Guys. It doesn't have to be state controlled okay? It can be a SV startup if you prefer :D

The government is just an example because they already handle ID for everyone, and they need it to provide their services. It makes sense for them to go digital at some point and to guarantee the ID.

I didn't know that Americans were so anti-American ^^

Re: I'm giving up on PGP

#232
post #228

Earlier quoted context omitted.

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

> Just get the national government to distribute RSA USB keys to every citizen. I lived in a country that did exactly that. And it was a disaster. The keys were trivially easy to steal, even by accident (personal experience here), and you still have the same trust problem as before, except that with a central authority now you do not have as much control. I have also used the electronic-signature-comes-with-your-ID-c…

It's 2FA, it's doesn't rely ONLY on the key for authentication and a token can be revoked easy if stolen.

The implementation and the technology has some challenges to be executed. Just like everyone tech projects, that doesn't have GooMicroZon people. Nothing special ^^

Re: I'm giving up on PGP

#233

Earlier quoted context omitted.

Any government who wants to bring 2FA to its citizens. Shipping a national backdoor is an entirely different topic. Please focus on the use case at hands.

I think that issue is central. You're describing a scheme with a central, trusted authority distributing keys. The question is, what's a central authority we can all trust? I think many people wouldn't trust any government. At that point, the design crumbles.

Well. You trust your government to issue national ID card and e-passports already.

Re: I'm giving up on PGP

#234
post #172
post #32

Earlier quoted context omitted.

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

>A technical criticism of PGP/GPG is of course also possible. The whole thing is a museum of early 1990s crypto, with default ciphers like CAST5 and messages not being authenticated - and even if the message is authenticated most parts of the PGP protocol are not, meaning that you got that big bunch of C code maintained by that one German guy over there that parses unauthenticated bytes that you shipped through half…

> IMO we should aim for a Crypto like Signal presents it;

You mean by leaking the plaintext in the device logs? By having to trust a single party which is known for being economical with the truth (e.g., when he was running a "Google anonymising" proxy via a domain name registered under a false name and address?, then complained when he got booted by the registrar)? By using some ad-hoc "encryption" method which has been hacked together rather than designed as such? By relying on non-FOSS, commercial services (Google push)?

The bloke behind Sl is high on hype and low on actual technological achievement or skill. Good marketer, that's how he made his money. Trust him at your own peril.

Re: I'm giving up on PGP

#235

Earlier quoted context omitted.

A functional WoT should be no more difficult to use than managing your Facebook friends or contacts on your phone. Neither of those are difficult tasks, and are achieved by normal users every day.

Yeah I'm sure it's ridiculously simple and all the experts here saying it looks like the idea itself is fundamentally flawed are wrong.

> all the experts here

Which experts? And what are those fundamental flaws?

Re: I'm giving up on PGP

#236
The proposed solution is to use Twitter to use Signal or Whatsapp. This forces your correspondents to use one of these centralized services, and also to run proprietary software to be able to use them.

I'm also irritated by GPG and OpenPGP's shortcomings, but it still gives people a way to contact you with reasonable security and without having to use specific proprietary services.

Re: I'm giving up on PGP

#237
post #32

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

> Web of Trust implies such a glaringly obvious visual metaphor that I am truly in awe that not a single program works that way.

Yeah, but it doesn't actually work. The fact that I know you (i.e., I'm willing to certify your identity) implies nothing about my trust in identities you certify. For all I know, you mint a new identity every second, and then use all those newly-minted identities to cross-sign one another's keys.

Re: I'm giving up on PGP

#238
post #13

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases…

> How do you distribute the one time pad in the first place? If you do it insecurely, it's a waste of time. If you can do it "securely", why not just use that secure channel to send the message in the first place?

Because you may not have any messages to send at the time of the secure exchange of OTPs. Do note that one time pads are (or at least were) commonly used in the military.

> But the question is, how do we get to the point where you know that you have the correct keys and you can trust them?

That is not a technological problem per se, but rather a social one. Imagine that when you exchange phone numbers (or Farcebook IDs, if you're into that) with your work colleagues, or friends, or fellow attendees at that developer meetup, you also exchanged public keys.

Mechanically, the interaction is at about the same level of complexity, and effectively, as has already been mentioned, the web of trust already exists (Farcebook, ChainedIn, and all the other bollocks).

If any of those decided to implement secure end-to-end comms using PGP and offered you the possibility of uploading your public key for dissemination to your "friends", PGP might become ubiquitous in a matter of weeks. At a smaller scale, German email provider GMX is doing exactly this, by the way.

Re: I'm giving up on PGP

#239
post #193

Earlier quoted context omitted.

I worked in IT for an engineering company that required all external emails to be PGP encrypted. Despite all engineers having Symantec PGP software installed and setup, training, and support of IT, they would often ignore this policy. The excuse, often valid, was it would require IT from both companies to setup the encrypted keys for the first time for new users. If the system is too complex for engineers, the idea o…

Well-run email clients and servers are in an OK state today regarding encryption, and the weaknesses that exist are more related to adoption than technology. Take a typical office setup: your email client communicates over TLS with your central mail server (e.g. Exchange, Postfix) to retrieve or submit messages. This is true with webmail clients like Gmail and Outlook Web Access, as well as ones like Outlook/Mail.app…

I would dispute your contention that 'most' ISPs support (opportunistic) TLS for SMTP. Looking at the email I receive, both at gmail and self hosted domains, almost no one will do TLS - only big internet companies like eBay. No clients that I'm aware of maintain a history of opportunistic TLS success.

Maybe Let's Encrypt will change TLS adoption but I doubt it. It would need Google/Hotmail/Yahoo to increase the spam score for non-encrypted mail. But it's still way too complicated.

Re: I'm giving up on PGP

#240

Earlier quoted context omitted.

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

Guys. It doesn't have to be state controlled okay? It can be a SV startup if you prefer :D The government is just an example because they already handle ID for everyone, and they need it to provide their services. It makes sense for them to go digital at some point and to guarantee the ID. I didn't know that Americans were so anti-American ^^

Being distrustful of your government is completely "American." Having the U.S. federal government issuing an ID that is mandatory would make many in the U.S. raise a huge stink.
Post reply on HN