Earlier quoted context omitted.
A bold statement like that without a source just screams bullshit.
I think tptacek thinks in a way where he's giving you charity in an uneven discussion, so he's not obligated to go further; perhaps harsh, but his reputation warrants a little pause before simply saying "bullshit".
Encrypted email is still a pain
321–330 of 450 posts
Re: Encrypted email is still a pain
#322The more this topic comes up, the more I start to wonder if the "difficulty" in email encryption is actually people just being lazy. We have IM and texting apps like Signal. You install, and if your friends install then you're secure. Most people skip verifying fingerprints, not doing IRL face to face verification. Yes the install process is simple and requires no real work to start encrypting things, but that still…
>I start to wonder if the "difficulty" in email encryption is actually people just being lazy I think it's a combination of this and perhaps some ignorance as to the implications of skipping these processes, hence they aren't taken seriously. I'm not sure if more education on this is the solution or not, since it seems a lot of people don't really care about these internals and don't want to take the time to understa…
Security education is a never ending battle. Just like "use condoms", "floss your teeth", "wash your hands", etc. It also changes. Today "Use a password manager" is the new "change your password".
Re: Encrypted email is still a pain
#323Earlier quoted context omitted.
Agree about Matrix. You get addresses such as @username:example.com , which work somewhat like email addresses. The example.com part is the homeserver, analogous to gmail.com or yahoo.com in emails. Users can communicate across homeservers. It's also fast to setup. Took me about 30 minutes to set up a homeserver and host a customized riot client to use it. It's not completely decentralized yet, and you can only use f…
Just to clarify: identity servers are strictly optional and are used just for mapping 3rd party IDs (3PIDs) such as phone numbers and email addresses to matrix IDs so you can be discovered or discover other users by 3PID. They are only centralised atm because we haven't really started to attack the problem of decentralising them. What we really need is a decentralised equivalent of Keybase, but nobody has really buil…
- The fact that it appears to be impossible to disable typing notifications ("X is typing...") and read receipts. This can change the nature of a conversation and really should be optional. Coming from IRC, it just feels plain creepy. A friend flat-out refused to use Riot because of this.
- The fact that device information is leaked to everyone who happens to be in the same channel. So I can join #matrix and click on any of the >5k users and see information about all the devices a particular user has used. Here's from one random person: "https://riot.im/app/ via Chrome on Mac OS", "https://riot.im/app/ via Chrome on Windows", E5823 (ah, J. Doe is using a Sony Xperia Z5 Compact!), etc. Sometimes things like "Joe's iPhone" is exposed -- and I don't think Joe had any idea of that. This is bad.
Re: Encrypted email is still a pain
#324Earlier quoted context omitted.
> Normal people --- and eventually the F-500's, too --- just use WhatsApp. Sure, but WhatsApp is a totally closed protocol owned by a company (Facebook) known for rampant issues with privacy. Security professionals have a responsibility to recommend open protocols like Signal that are dedicated to privacy.
This is the "have you stopped beating your wife yet" of security arguments.
Re: Encrypted email is still a pain
#325Earlier quoted context omitted.
The fact that Osama Bin Laden didn't use PGP should be the final nail in its coffin.
That the NSA said GPG was gsme over for mass collection in the Snowden lesks should be a reason for everyone to try to improve its UI.
Re: Encrypted email is still a pain
#326Earlier quoted context omitted.
> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…
Why use PGP anymore when you can use Keybase and the next generation of key management? Instead of having one master key for your identity, the paradigm is changed: Identity is a set of claims "X on domain A is Y on domain B". That's it. "Domain" can refer to a server-based service such as reddit, or a client app on a device. Such proofs are easy: 1) For public identity on sites which don't support this scheme, X sim…
I really want to be able to type Twitter, Hacker News or Github names into emails.
Re: Encrypted email is still a pain
#327It presents (at least on my system) a very clear prompt to type a passphrase. Maybe you should blame your distribution instead of gpg?
Re: Encrypted email is still a pain
#328Earlier quoted context omitted.
There are federated options for messengers, the fact that the current darlings aren't is not a mark against the option itself. Riot exists. Can you find a security expert RECOMMENDING email? That would be a better example of how it's not a consensus, like you claim.
Riot might be a great platform for doing business, but it's pretty useless for any other kind of activity. If you're a political activist having an app called 'Riot' on your phone or computer is not going to look good to anyone in law enforcement.
Re: Encrypted email is still a pain
#329Earlier quoted context omitted.
That the NSA said GPG was gsme over for mass collection in the Snowden lesks should be a reason for everyone to try to improve its UI.
thats a pretty terrible argument. And how it follows for your own logic is beyond me.
Re: Encrypted email is still a pain
#330Earlier quoted context omitted.
> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…
You know, I've been having this conversation ever since PGP first came into existence. And much as I love the idea of encryption, and despite having invested lots of time in arguing for the right to encrypt and to share encryption algorithms etc. etc. I've always had to admit that if you're not a geek who loves computing for its own sake then encrypting all your email is a massive pain in the ass, whose costs substan…