Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

241–250 of 350 posts

Re: I'm giving up on PGP

#241
post #206

Earlier quoted context omitted.

99% of crypto would work just fine if you appended an OTR-like protocol over the top of email. First email is "hey we're interested in blah..." and is sent in the clear. Then have the message window change color as subsequent emails get the protocol more secured.

I hate color coding. I'm in the 8-12% of men that have red-green deficient vision. You can use 10% as a rule of thumb. If I'm not mistaken in my probability math, that means in a group of 5 men, there is a 50% chance one of them is "color blind." Yet the world insists on using red/green as bad/good indicators. Drives me nuts.

You are mistaken. If probability of each of the 5 men being colorblind is independent (so eg. they're not related etc), then there's a 41% chance that at least one of them is (1 - 0.9⁵).

(There's a 33% chance that exactly one of them is: 0.1 × 0.9⁴ × ⁵C₁).

Re: I'm giving up on PGP

#242
post #228

Earlier quoted context omitted.

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

> Just get the national government to distribute RSA USB keys to every citizen. I lived in a country that did exactly that. And it was a disaster. The keys were trivially easy to steal, even by accident (personal experience here), and you still have the same trust problem as before, except that with a central authority now you do not have as much control. I have also used the electronic-signature-comes-with-your-ID-c…

>The keys were trivially easy to steal, even by accident

So distribute keys on smart cards that don't allow you to export the key. This is what Estonia does, and - concerns about their election infosec aside - it seems to work pretty well.

Re: I'm giving up on PGP

#243

Earlier quoted context omitted.

I think that issue is central. You're describing a scheme with a central, trusted authority distributing keys. The question is, what's a central authority we can all trust? I think many people wouldn't trust any government. At that point, the design crumbles.

Well. You trust your government to issue national ID card and e-passports already.

I'm guessing you are from Europe because the idea of distrusting your government appears to be really foreign to you. According to Wikipedia, "The passport possession rate of the U.S. was approximately 39% of the population in 2015."

Re: I'm giving up on PGP

#244

Earlier quoted context omitted.

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

Why the fuck would you ever insert a government-provided USB key into any computer you actually cared about, much less actually use any government-provided key? The national government is the prime adversary . I mean, seriously, Alice and Bob want to communicate, and your solution is that they should use Eve as a courier!??

I wonder if there's a niche for a USB firewall dongle that you can plug anything in with and it will guarantee it's only treated as a file system or something else benign.

Re: I'm giving up on PGP

#245
post #193

Earlier quoted context omitted.

I worked in IT for an engineering company that required all external emails to be PGP encrypted. Despite all engineers having Symantec PGP software installed and setup, training, and support of IT, they would often ignore this policy. The excuse, often valid, was it would require IT from both companies to setup the encrypted keys for the first time for new users. If the system is too complex for engineers, the idea o…

Well-run email clients and servers are in an OK state today regarding encryption, and the weaknesses that exist are more related to adoption than technology. Take a typical office setup: your email client communicates over TLS with your central mail server (e.g. Exchange, Postfix) to retrieve or submit messages. This is true with webmail clients like Gmail and Outlook Web Access, as well as ones like Outlook/Mail.app…

There are defenses against those attacks, though. You can configure your SMTP server to require TLS, and to accept only path-validated TLS certificates from trusted certificate authorities. This will prevent an adversary from forcing your traffic to plaintext, and will prevent them from substituting a bogus self-signed certificate. With these protections in place, one can achieve a fairly good measure of security with basic email.

This only works if you're also forcing DNSSEC: otherwise, the attacker can substitute their own MX in your DNS responses.

Re: I'm giving up on PGP

#246
post #30

Good points, but also I would like to point out that https://www.usenix.org/system/files/1401_08-12_mickens.pdf linked from the blog post was an entertaining read so for anyone that didn't read said PDF, do.

There's quite a few Mickens rants, and they're all well written. Edit: Link http://mickens.seas.harvard.edu/wisdom-james-mickens

Guess I have some homework- thanks for linking these!

Re: I'm giving up on PGP

#247

Earlier quoted context omitted.

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

Guys. It doesn't have to be state controlled okay? It can be a SV startup if you prefer :D The government is just an example because they already handle ID for everyone, and they need it to provide their services. It makes sense for them to go digital at some point and to guarantee the ID. I didn't know that Americans were so anti-American ^^

It's a bit of a Continental European view that "they [the national government] already handle ID for everyone". Universal government ID isn't historically the case in countries descended from the UK.

Re: I'm giving up on PGP

#248

People who use PGP keys, can you give examples of your use? I'm genuinely curious. Who are you contacting, or who is contacting you? The author says he only receives 2 encrypted emails a year. Not only do I not have a PGP key, I don't think I've ever found myself in a situation where it was even an option to use one.

- All internal company emails. - Mailing Lists

Side note: using pgp with MacOs Mail is super easy https://gpgtools.org/ (the project is currently working on Sierra support)

Re: I'm giving up on PGP

#249

Earlier quoted context omitted.

IMHO, the biggest issue with matrix, is that there's no free hosted solution for using my own domain/email. Sure, I can rent a server and set up my own, but that's a huge commitment to "try out" a protocol which non of my acquaintances uses yet.

hm, can you point me at an email provider who provides free SMTP/IMAP/webmail or XMPP hosting for custom domains? I may be missing something, but I can't think of one... The model is that you can try it out on the matrix.org server via riot.im or something, and then run your own if you like what you see :)

Zoho actually provides custom domain email for free.

Re: I'm giving up on PGP

#250

Earlier quoted context omitted.

Well. You trust your government to issue national ID card and e-passports already.

I'm guessing you are from Europe because the idea of distrusting your government appears to be really foreign to you. According to Wikipedia, "The passport possession rate of the U.S. was approximately 39% of the population in 2015."

> distrusting your government appears to be really foreign to you.

That "U.S. Government" collecting, indexing and analyzing all data of any citizen must be an entirely different entity from the "United States Government" after all.

Post reply on HN