Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

271–280 of 350 posts

Re: I'm giving up on PGP

#271

Earlier quoted context omitted.

FWIW: your point--and it's a good one--is better made without the yelling. And to answer you, though I don't speak for the person you were relying to: the U.S. government isn't even in my threat model. If the Eye of Sauron points my way, I lose. And so, given that as a prior, a universally trustable third party is not a bad idea. The implementation might totally suck (and I think it's a better practice to have a wide…

I take your point - though I was not intending to yell, but to represent my state of alarm and bafflement, as the original poster's worldview is both alien and frightening. It's as though someone were circulating one of those "modest proposals" to improve automobile security by installing a sharp metal spike on the center of every steering wheel, without realizing that these things are supposed to be jokes. A univers…

There's a power curve though, yeah? That most powerful agent can just drag you off and apply rubber-hose cryptography. Or just drone your ass. At some point, worrying about what else they can do is kind of a whateverburger.

Re: I'm giving up on PGP

#272

Earlier quoted context omitted.

I take your point - though I was not intending to yell, but to represent my state of alarm and bafflement, as the original poster's worldview is both alien and frightening. It's as though someone were circulating one of those "modest proposals" to improve automobile security by installing a sharp metal spike on the center of every steering wheel, without realizing that these things are supposed to be jokes. A univers…

There's a power curve though, yeah? That most powerful agent can just drag you off and apply rubber-hose cryptography. Or just drone your ass. At some point, worrying about what else they can do is kind of a whateverburger.

Sure, so the point is to avoid their notice. That's harder to do when they can snoop on your communications.

Re: I'm giving up on PGP

#273

Earlier quoted context omitted.

I think that issue is central. You're describing a scheme with a central, trusted authority distributing keys. The question is, what's a central authority we can all trust? I think many people wouldn't trust any government. At that point, the design crumbles.

Well. You trust your government to issue national ID card and e-passports already.

The US has strange hangups about national IDs.

Re: I'm giving up on PGP

#274

Earlier quoted context omitted.

Well. You trust your government to issue national ID card and e-passports already.

I'm guessing you are from Europe because the idea of distrusting your government appears to be really foreign to you. According to Wikipedia, "The passport possession rate of the U.S. was approximately 39% of the population in 2015."

Do you think only 39% of Americans because the other 61% are all terrified of their government? Or might it be because international travel is a luxury not everyone can afford?

Re: I'm giving up on PGP

#275
post #244

Earlier quoted context omitted.

Why the fuck would you ever insert a government-provided USB key into any computer you actually cared about, much less actually use any government-provided key? The national government is the prime adversary . I mean, seriously, Alice and Bob want to communicate, and your solution is that they should use Eve as a courier!??

I wonder if there's a niche for a USB firewall dongle that you can plug anything in with and it will guarantee it's only treated as a file system or something else benign.

The device could be something like a modified USB condom, but with more processing power. It would have to have all drivers locked unless a sensor verified that nothing was plugged into the suspicious end, and use a fundamentally limited set of drivers. On connection, it looks for any filesystems on the suspicious device, mounts them, and offers them up by proxy as filesystems to the host machine. Nice idea.

Re: I'm giving up on PGP

#276
post #69

Earlier quoted context omitted.

Private keys accessible to the browser is the worst model. I don't think this was ever taken seriously at Google either...

Private key required in the browser is bad. However if we had a system where those people that want or care can key their keys offline (or on a Smartcard) while those that don't want. Protonmail with SRP and 2FA where a attack has to pretty tricky stuff but you still get a e2e system is far better then what we have now. Its a far more involved attack to just look at your old emails, and its easier to detect. We will…

> Protonmail with SRP and 2FA where a attack has to pretty tricky stuff but you still get a e2e system is far better then what we have now. Its a far more involved attack to just look at your old emails, and its easier to detect.

Can you explain how this is better than Google End-to-End? (Which isn't completed, I know.)

Or even how it's worth implementing over regular webmail in the first place?

Extensions are obviously not optimal, for the very same reason crypto in JavaScript is not good: timing attacks, cache attacks, optimizations, secure storage (in-memory and on-disk), random-number generation, verifiability, ....

Protonmail suffers from that too. Except it's also subject to key exfiltration. Without an exploit. The server simply promises not to send malicious JavaScript.

It isn't significantly more involved for an attacker who has breached their servers to send malevolent code. It's also not easy to detect.

> We will never have a useable experience for all user if we do not accept compromises.

There are usable end-user interfaces capable of featuring secure cryptography.

Desktop applications. Mobile apps. Browser extensions. Hardware tokens (U2F).

Those can be audited. Inspected. Users can freeze updates.

Trying to implement secure cryptography in JavaScript that is fetched repeatedly from an assailable server is just asking for trouble.

> GPG is already not perfect and we should move away from it anyway

Yes, but that doesn't mean ignoring the advancements that have been made in modern security.

The most appropriate response to securing email is still this: Don't, use a secure messenger; or use out-of-band encryption. It's likely to remain that way forever.

Re: I'm giving up on PGP

#277
post #241

Earlier quoted context omitted.

You are mistaken. If probability of each of the 5 men being colorblind is independent (so eg. they're not related etc), then there's a 41% chance that at least one of them is (1 - 0.9⁵). (There's a 33% chance that exactly one of them is: 0.1 × 0.9⁴ × ⁵C₁).

Thanks. It's been too long since I've studied statistics. Might be time to watch some khan academy. Oh, I see. Assuming probability that a man is not colorblind is 0.9, then you found the probability of none of them being colorblind and subtracted that amount from 1 to find the other side. For anyone reading this that was bothered by my use of a specific gender, it's because colorblindness occurrence is significantly…

An ever-apologetic, yet demanding complainer.

The entire world should bend to your will, and court your color blind deficiency, and yet you curtsy to the possible perception of a non-neutral, gender-specific rant.

Honestly. Who fucking cares? Just say your piece, and dispose of the chivalry, since it too is technically sexist. Wallow in the reality that someone will be annoyed by such pretentiousness.

Meanwhile, color coding can use HSB models to still permit differentiability via brightness contrast, and font weight, when coding. It's not like us color coders are ignoramuses, you insensitive clod!

Re: I'm giving up on PGP

#278
post #32

I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification. It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "…

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

> I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue.

The average person already struggles to even use a computer and to accomplish tasks which seem very basic to us. [0]

I can't imagine them figuring out how to use PGP. The WoT is a complicated system to understand for even technically proficient users, let alone average ones.

[0] https://www.nngroup.com/articles/computer-skill-levels/

Re: I'm giving up on PGP

#279
post #32

Earlier quoted context omitted.

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

I have to partially disagree with that. Calling PGP an utter failure is an understatement. Just like calling a cat a small tiger. PGP is possibly the WORST experience in usability for any well known software that ever lived. This thing should be taught in courses for decades to come as how to fail a product by 1) having no UI 2) no integrations with anything 3) zero usability 4) not even trying to give a fuck about n…

The first half of what you said, everything about PGP usability, is on point.

The second half--the federal government as centralized national PKI, generating everyone's private keys for them--is hilariously terrible.

I can almost hear Moxie, Matt Green, Trevor Perrin, and every infosec researcher and crypto engineer and privacy advocate facepalming in unison.

Re: I'm giving up on PGP

#280
post #241

Earlier quoted context omitted.

You are mistaken. If probability of each of the 5 men being colorblind is independent (so eg. they're not related etc), then there's a 41% chance that at least one of them is (1 - 0.9⁵). (There's a 33% chance that exactly one of them is: 0.1 × 0.9⁴ × ⁵C₁).

I think a Poison distribution would be more appropriate here, so the probability of 1 man in 5 being colorblind, assuming 10% of the population on average is colorblind, is: e^-0.5*sum((i)->(0.5^i/factorial(i)), 1:5) = ~39%

I don't believe so - it's n instances of a bi-valued random variable, IID. It's exactly the case the binomial distribution covers.
Post reply on HN