Live data from Hacker News

I'm giving up on PGP

blog.filippo.io

291–300 of 350 posts

Re: I'm giving up on PGP

#291
post #64

Earlier quoted context omitted.

The standard for adoptability isn't the average person at their peak hours of attention and focus. It's the drunk teenager at 2 in the morning fumbling around in the dark.

A functional WoT should be no more difficult to use than managing your Facebook friends or contacts on your phone. Neither of those are difficult tasks, and are achieved by normal users every day.

What is a “functional WoT”? The main trouble here: it's a really hard conceptually, if you delegate that hardness to 3rd party you will completely lose WoT essence.

Re: I'm giving up on PGP

#292

Earlier quoted context omitted.

I think that issue is central. You're describing a scheme with a central, trusted authority distributing keys. The question is, what's a central authority we can all trust? I think many people wouldn't trust any government. At that point, the design crumbles.

Well. You trust your government to issue national ID card and e-passports already.

Just because I have and use such passport does not mean I think its a good idea or trust it completly.

Re: I'm giving up on PGP

#293

People who use PGP keys, can you give examples of your use? I'm genuinely curious. Who are you contacting, or who is contacting you? The author says he only receives 2 encrypted emails a year. Not only do I not have a PGP key, I don't think I've ever found myself in a situation where it was even an option to use one.

  - I use it as my ssh key
  - I use it to sign my git commits and tags
  - I use it to share credentials with people (e.g. "hey bob, what's the password to the shared XXX account" => pastes to me in IM encrypted to me)
  - I use it to encrypt passwords in my password manager

Re: I'm giving up on PGP

#294
post #254
post #253

Earlier quoted context omitted.

True that it would hurt public opinion even further of the agencies if they were to take him out - but I thought he only revealed a portion of what he grabbed.

My understanding is that he handed everything off to the journalists.

Yes, for precisely the reason that he did not want to be the arbiter of what is released. That's probably why he's still alive. It was a good decision

Re: I'm giving up on PGP

#295
post #113

> Yeah, about that. I never ever ever successfully used the WoT to validate a public key. If you ever installed a Debian package then you did. A long-term identity as "Bob Jones" might not be terribly useful - but that's not the kind of long-term identity we care about a lot in real life either. A long-term identity as "Debian release manager" or "Signatory on bank account xyz" or even "Wikileaks committee member" is…

> If you're using iOS you've already given up against state-level attackers. Wasn't the recent apple vs FBI debacle evidence to the contrary?

They might debate in public and make a deal in private, you may never know.

Re: I'm giving up on PGP

#296
post #113

> Yeah, about that. I never ever ever successfully used the WoT to validate a public key. If you ever installed a Debian package then you did. A long-term identity as "Bob Jones" might not be terribly useful - but that's not the kind of long-term identity we care about a lot in real life either. A long-term identity as "Debian release manager" or "Signatory on bank account xyz" or even "Wikileaks committee member" is…

> If you're using iOS you've already given up against state-level attackers. Wasn't the recent apple vs FBI debacle evidence to the contrary?

Apple was a part of the NSA's prism program.

Re: I'm giving up on PGP

#297

Earlier quoted context omitted.

Guys. It doesn't have to be state controlled okay? It can be a SV startup if you prefer :D The government is just an example because they already handle ID for everyone, and they need it to provide their services. It makes sense for them to go digital at some point and to guarantee the ID. I didn't know that Americans were so anti-American ^^

Being distrustful of your government is completely "American." Having the U.S. federal government issuing an ID that is mandatory would make many in the U.S. raise a huge stink.

Good thing that social security number thing never took off I suppose.

Re: I'm giving up on PGP

#298
post #172
post #32

Earlier quoted context omitted.

> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Tr…

>A technical criticism of PGP/GPG is of course also possible. The whole thing is a museum of early 1990s crypto, with default ciphers like CAST5 and messages not being authenticated - and even if the message is authenticated most parts of the PGP protocol are not, meaning that you got that big bunch of C code maintained by that one German guy over there that parses unauthenticated bytes that you shipped through half…

> It might be worthwhile to bring Signal (or atleast the idea) to other protocols like E-Mail.

I like this idea a lot!

Re: I'm giving up on PGP

#299

Earlier quoted context omitted.

> Yet the world insists on using red/green as bad/good indicators. Drives me nuts. Well, it has to use something, and other people would be colorblind in other colors, plus some will be blind too. In this case, one would expect there'd be some OS-wide color utility to alter colors to the ones the user can discern.

Yes, but these other ones are far more rare. Also there are shades that make it so much assessable for people. Almost every day I will ask someone what color something is because of poor selection. Chances are you have a color blind person in you office, just run visualizations by them really quick.

> Chances are you have a color blind person in you office, just run visualizations by them really quick.

This is a great check, but I also recommend trying things just in greyscale as a simple test and installing something like Color Oracle [0]. Also, most of the problems can be solved by looking for an already existing solution, like swapping your heatmap colour scales for viridis [1].

The most important thing is recognising that these kinds of issues exist and pro-actively looking for good current solutions (the same applies for things like trying to ensure your site works well with screen readers).

I'd love to hear of more tools or other things that can help if people have suggestions!

0 http://colororacle.org/

1 https://cran.r-project.org/web/packages/viridis/vignettes/in...

Re: I'm giving up on PGP

#300
post #25

Earlier quoted context omitted.

This has been my experience. The only "good" experience I've had with encrypted messages through email was a back and forth exchange I had with a fellow Keybase user where I manually copy and pasted blocks of encrypted text into/out of their web interface.

From my experience - the only PGP users I've spoken to were all on Keybase or interested in a Keybase invite. It was about 6 people for the entirety of last year - and 3 people this year...it certainly has a problem of "almost nobody uses it" but Keybase seems to have eased things slightly - or at least made it easier to discover people who also use PGP. I see the two problems being "People don't bother with the clun…

Warms my heart: http://www.cryptopals.org/
Post reply on HN