This article: what a shitfest. But seriously, I was expecting some actual discussion about how GPG still isn't easy (or possible for that matter) in modern webmail clients, or even something relating to the usability of common GPG GUIs, but instead just got a guy complaining about how he was pressing enter too fast and missed a dialog box, among other nonsense complaints. Personally, the GPG CLI acts exactly as I exp…
A messaging standard that only advanced users can use is basically useless. That's the point of the article.
Encrypted email is still a pain
121–130 of 450 posts
Re: Encrypted email is still a pain
#122Earlier quoted context omitted.
Yes with no control over what happens to your key and you don't know if your message has been encrypted after it is sent and by default you aren't even told if the key of your recipient changes.
By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with: * The EFF * Moxie Marlinspike * Matthew Green * Bruce Schneier * Isis Lovecruft from Tor * the grugq * Matt Blaze * Avi Rubin * Steve Bellovin * Joseph Lorenzo Hall * Bart Preneel * Peter Honeyman * Jon Callas (who cofounded PGP Corp) * Paulo Barreto ... and about 50 more experts equally respected in the f…
And the owner of the Signal protocol (which is what WhatsApp uses). Obviously he's not going to argue against it.
Re: Encrypted email is still a pain
#123Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…
> at best you're attempting to tunnel encrypted messaging over an unencrypted transport. That covers pretty much all communication encryption: ultimately, encrypted data goes out over an unencrypted link. > A protocol that leaks metadata, including some message content, at the envelope layer. That is indeed the major problem I have with it. > Hundreds of millions of users that primarily access messages through browse…
You seem to be implying that I have one computer at home. I mostly use the computer in my pocket, but sometimes I use "my" computer in "My office" at home. Sometimes I use "my wife's computer". Many people I know have a computer attached to their tv. I'm looking into putting a computer in my garage. Someday I'm likely to get a laptop or tablet computer for travel (I've had these in the past).
We need to get off the mindset of one computer per person - it was never really true, but for the average person today it is less true.
Re: Encrypted email is still a pain
#124Earlier quoted context omitted.
> No, I fully understand the problem. If Google Mail vanished tomorrow, a pretty large number of people would probably stop emailing altogether. The number of people for whom that's true increases every year. I highly doubt that's true. Email is pretty essential to the functionality of the internet, from signing up accounts to getting notifications, to just plain discussions with professionals. It's pretty much the o…
Three responses: * Email remains important for middle-class Americans because it's used for business. But that is a small subset of the whole population, including very large numbers of Americans. * For almost all those users, email might as well be a Google, Yahoo, or Microsoft product. * Every year, the number of people and businesses that rely on email gets smaller --- in the last 5 years or so, by something like…
Bolting on decentralization works about as well as bolting on security.
Re: Encrypted email is still a pain
#125Re: Encrypted email is still a pain
#126Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…
All of those messingers are terrible - in email you cannhave multiple conversations with the same person by design. In thoae you can't. There is no messinger with decent history search.
Re: Encrypted email is still a pain
#127S/MIME is supported by almost all email clients.
S/MIME is far less of a pain (but still some pain and could be improved).
It has a model of how to verify that keys belong to the right person, that actually works in practice in contrast to GPG where you basically have to verify keys by hand (adversarial CAs are a problem, but probably only for a tiny amount of people).
Re: Encrypted email is still a pain
#128Earlier quoted context omitted.
If you are an active target of a tier 1 state, your endpoint will be compromised, your decrypted communication will be read, and no cryptosystem will prevent this.
Furthermore, if you're using PGP to evade a state-level adversary, the odds are overwhelming that you've own-goaled yourself many times over: * You keep plaintext archives and drafts of your messages, because that's a fundamental feature of email clients going back 3 decades. * You use a server-mediated PGP provider like Protonmail that has your security one surreptitious Javascript injection on an XHR call away from…
To my knowledge, mutt doesn't store decrypted archives. Drafts are stored in /tmp which can be a filesystem stored in RAM. I think using Mutt also takes care of your second point.
Your third point is the biggest problem with any system where security is bolted on (e.g. SMTP, POTS, etc.) - your end may be secure but your interlocutor is liable to compromise you one way or another. Though, as you say, this isn't a fundamental property of all encrypted messaging systems.
Re: Encrypted email is still a pain
#129Earlier quoted context omitted.
I use PGP pretty regularly, too. But what does that have to do with the comment I wrote?
Encrypted email for this user group is certainly not over, and there is still no realistic alternative for it. So PGP is not going to go away completely.
I hope PGP remains around for people who do need it. There are people who have a real need for secure communication, and they are probably able to invent a cover story to explain your meta-data leaks. (everyone knows I buy widgets and from him: it is no surprise that we don't want details about our negotiations public)
Re: Encrypted email is still a pain
#130Earlier quoted context omitted.
Yes with no control over what happens to your key and you don't know if your message has been encrypted after it is sent and by default you aren't even told if the key of your recipient changes.
By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with: * The EFF * Moxie Marlinspike * Matthew Green * Bruce Schneier * Isis Lovecruft from Tor * the grugq * Matt Blaze * Avi Rubin * Steve Bellovin * Joseph Lorenzo Hall * Bart Preneel * Peter Honeyman * Jon Callas (who cofounded PGP Corp) * Paulo Barreto ... and about 50 more experts equally respected in the f…
GP was questioning the implementation and OP is merely identifying a clear weakness (regardless of who you says, it is a trade-off). Not quite an appeal to authority, but it's pretty damn close.
What exactly about the post is a discredited argument? I'm genuinely curious. WhatsApp can be doing anything behind the scenes without clients knowing about it, how is questioning this a bad thing?