Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

251–260 of 350 posts

Re: I'm giving up on PGP

#251

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

>we have a deep conceptual usability issue here. yes, yes we do. All this stuff seems easy if you have the curiosity so spend hours and hours reading dry documentation about how it works. This is to say nothing of actually getting your hands on the tech and inevitably having problems that require more hours of forum searchs, IRC, and other time drains. It's not that "regular" people are too stupid to do this, they ju…

And it's not just regular people, it's developers, programmers. Most devs I know look at pgp and are totally capable of figuring it out, but what they say basically boils down to: ain't nobody got time for that

Re: I'm giving up on PGP

#252

Earlier quoted context omitted.

Well. You trust your government to issue national ID card and e-passports already.

I'm guessing you are from Europe because the idea of distrusting your government appears to be really foreign to you. According to Wikipedia, "The passport possession rate of the U.S. was approximately 39% of the population in 2015."

Yeah I am.

I guess that makes sense. People in the UK don't have any "national ID card". Must be a culture thing.

I guess that makes sense. That's why I have to go through fucking stupid private background check agencies for everything in the UK.

Re: I'm giving up on PGP

#253
post #204
post #51

Earlier quoted context omitted.

I like: "It’s like, websites are amazing BUT DON’T CLICK ON THAT LINK, and your phone can run all of these amazing apps BUT MANY OF YOUR APPS ARE EVIL, and if you order a Russian bride on Craigslist YOU MAY GET A CONFUSED FILIPINO MAN WHO DOES NOT LIKE BEING SHIPPED IN A BOX. It’s not clear what else there is to do with computers besides click on things, run applications, and fill spiritual voids using destitute mail…

> For his claim "YOU’RE STILL GONNA BE MOSSAD’ED UPON" I still don't know how to interpret the fact that Snowden seems to be relatively fine. Maybe that he had the idea about the blind spots of the system in which he worked. What reason would any agency have to un-live Snowden? Any damage he has done was already done in HK and before; he has nothing more to reveal. It would only turn public opinion against the agenci…

True that it would hurt public opinion even further of the agencies if they were to take him out - but I thought he only revealed a portion of what he grabbed.

Re: I'm giving up on PGP

#254
post #253
post #204

Earlier quoted context omitted.

> For his claim "YOU’RE STILL GONNA BE MOSSAD’ED UPON" I still don't know how to interpret the fact that Snowden seems to be relatively fine. Maybe that he had the idea about the blind spots of the system in which he worked. What reason would any agency have to un-live Snowden? Any damage he has done was already done in HK and before; he has nothing more to reveal. It would only turn public opinion against the agenci…

True that it would hurt public opinion even further of the agencies if they were to take him out - but I thought he only revealed a portion of what he grabbed.

My understanding is that he handed everything off to the journalists.

Re: I'm giving up on PGP

#257
post #228

Earlier quoted context omitted.

> Just get the national government to distribute RSA USB keys to every citizen. I lived in a country that did exactly that. And it was a disaster. The keys were trivially easy to steal, even by accident (personal experience here), and you still have the same trust problem as before, except that with a central authority now you do not have as much control. I have also used the electronic-signature-comes-with-your-ID-c…

>The keys were trivially easy to steal, even by accident So distribute keys on smart cards that don't allow you to export the key. This is what Estonia does, and - concerns about their election infosec aside - it seems to work pretty well.

> So distribute keys on smart cards that don't allow you to export the key

That's what I covered in the second paragraph. :-)

The thing is, both those implementations were a disaster from either a technological or a security point of view. We're not even getting into whether a central source of trust is a good idea or not (you will look at the state of HTTPS and make up your own mind on that). So, to repeat, proper security is hard.

Re: I'm giving up on PGP

#258
post #241

Earlier quoted context omitted.

I hate color coding. I'm in the 8-12% of men that have red-green deficient vision. You can use 10% as a rule of thumb. If I'm not mistaken in my probability math, that means in a group of 5 men, there is a 50% chance one of them is "color blind." Yet the world insists on using red/green as bad/good indicators. Drives me nuts.

You are mistaken. If probability of each of the 5 men being colorblind is independent (so eg. they're not related etc), then there's a 41% chance that at least one of them is (1 - 0.9⁵). (There's a 33% chance that exactly one of them is: 0.1 × 0.9⁴ × ⁵C₁).

I think a Poison distribution would be more appropriate here, so the probability of 1 man in 5 being colorblind, assuming 10% of the population on average is colorblind, is:

    e^-0.5*sum((i)->(0.5^i/factorial(i)), 1:5) = ~39%

Re: I'm giving up on PGP

#259

Earlier quoted context omitted.

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

Why the fuck would you ever insert a government-provided USB key into any computer you actually cared about, much less actually use any government-provided key? The national government is the prime adversary . I mean, seriously, Alice and Bob want to communicate, and your solution is that they should use Eve as a courier!??

Not everyone is using encryption to stand up to the man... the national government isn't everyones prime adversary...
Post reply on HN