Live data from Hacker News

Cryptography Dispatches: Hello World, and OpenPGP Is Broken

buttondown.email

41–50 of 72 posts

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#41
post #35

Earlier quoted context omitted.

I am not trying to win a popularity contest. If you care about secure messaging, and want to be sure you about who you are talking to -- then you have to use something like pgp. I don't think the number of people using something invalidates a technology's technical merits. All we now have is a bunch of people thinking they are secure to one day have a very rude awakening not if, but when their communications are comp…

The only people who agree with you about the need for PGP in serious secure messaging are members of the PGP cheering section. They're an old and venerable social organization dating back to the pre-HMAC CFB-mode cryptography in PGP itself. I have nothing bad to say about their justified and ancient society other than that they are wrong about everything involving cryptography and that they recommend tools that get p…

If someone solved the UI/UX problems with gnupg, and came up with a more elegant method of exchanging/validating keys (or even just an alternate keyserver infrastructure with better properties), wouldn't that solve the problem?

Edit: how about a response instead of a downnvote, anonymous detractor?

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#42
post #35

Earlier quoted context omitted.

The only people who agree with you about the need for PGP in serious secure messaging are members of the PGP cheering section. They're an old and venerable social organization dating back to the pre-HMAC CFB-mode cryptography in PGP itself. I have nothing bad to say about their justified and ancient society other than that they are wrong about everything involving cryptography and that they recommend tools that get p…

PGP is a protocol, there is nothing wrong with it. If you want to complain about good PGP based apps that is a entirely different argument (and it think that is what you are arguing). Signal is not a protocol, it is a application. It uses open whisper (or some mutation of it) as its underlying protocol. That being said, you are still relying on trust provided by the signal servers that they properly authenticated you…

Both of those statements are false.

There are clear things wrong with the PGP protocol. PGP predates authenticated encryption (let alone modern AEAD ciphers) and the hacks PGP came up with to authenticate ciphertext resulted both in stripping attacks and, indirectly, in the Efail attack from last year. It was also Signal's linear packet based key format that resulted in the GnuPG/SKS attacks.

Signal is a protocol; in fact, it was "Signal Protocol" that won the Levchin prize. Signal also doesn't verify identities with phone numbers.

These are just basic, fundamental factual problems with your claims. We're not even getting close to serious comparisons between the two systems; we haven't even talked about forward secrecy, compromise repair, modern primitives, complexity, and UX.

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#43
post #5

Can we stop saying that pgp is busted and just talk about how the keyservers are the problem with how people decides to exchange keys ? I don't use key servers. So when I get an encrypted message from my friend I have no issues. Allowing a third party such as a key server to play some role in veifiing the authenticity of a key is basically broken from tht start, and has nothing to do with pgp it's self.

Well, I always ignore the more grandiose claims - since there is currently no alternative for GPG, and installing Electron apps for Signal or Wire (which then use a single centralized server) really isn’t a viable GPG alternative

But even if you don’t agree with the argument that federation is dead and we truly need Electron apps (with eternally outdated Chrome instances) for secure communication, still you have to admit that PGP is arcane, the cryptography is not modern, and people by and large are ignoring the “web of trust” system. PGP needs a dramatic overhaul, at the end it won’t really be PGP.

(I am not sure if there isn’t a double ratchet system working in federated way. Jabber with OMEMO/OTRv3? Matrix? I don’t know)

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#44
I've seen the link from this article before about alternatives to PGP and it bugs me for two reasons. One is the implication that everyone should write all software in Go. The other is that when you swap out one system for half a dozen, you now need to identify yourself half a dozen different ways. That seems confusing.

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#45
post #42

Earlier quoted context omitted.

PGP is a protocol, there is nothing wrong with it. If you want to complain about good PGP based apps that is a entirely different argument (and it think that is what you are arguing). Signal is not a protocol, it is a application. It uses open whisper (or some mutation of it) as its underlying protocol. That being said, you are still relying on trust provided by the signal servers that they properly authenticated you…

Both of those statements are false. There are clear things wrong with the PGP protocol. PGP predates authenticated encryption (let alone modern AEAD ciphers) and the hacks PGP came up with to authenticate ciphertext resulted both in stripping attacks and, indirectly, in the Efail attack from last year. It was also Signal's linear packet based key format that resulted in the GnuPG/SKS attacks. Signal is a protocol; in…

> Both of those statements are false. Pop on over to wikipeida, you will how wrong you actually are.

>> "Signal uses standard cellular mobile numbers as identifiers" >> "The applications include mechanisms by which users can independently verify >> the identity of their messaging correspondents and the integrity of the data >> channel."

That is what I described, its trust us first, and maybe verify later if you think of it.

>> "Open Whisper Systems introduced the second version of their TextSecure Protocol >> (now Signal Protocol)"

Looks like it is Open Whisper, just V2 and renamed... Well maybe TextSecure.

> hacks PGP came up with to authenticate ciphertext resulted both in stripping attacks and, indirectly, in the Efail attack from last year.

A quick look at Efail shows clients were at fault and the fix was fix was patching clients. I can assure you my email client had no such issue. So again, you are blaming something on PGP that really just involved PGP. If Signals code has a bug in it too can leak encrypted messages after the client decrypts them.

> key format that resulted in the GnuPG/SKS attacks

Again you are back on keyservers, a method of offline verification to a 3rd party.

> Signal also doesn't verify identities with phone numbers.

Yes it does, unless you do the second step of verification, which is not done by default. Have you used signal before? When I installed it on my phone magically people I knew showed up base off -- what is that? A phone number.

And again Wikipedia - " Signal uses standard cellular mobile numbers as identifiers, "

> These are just basic, fundamental factual problems with your claims.

You keep conflating things with PGP that are not PGP, thus I have to refute insane statements that don't have to do with pgp, but things like email clients, or now how signal actually works. You thus far have just said I am wrong, but yet not described how any of this works. Yet I am here pointing to and describing in great detail how you are wrong. Simply saying I am wrong, and not demonstrating it does not make you right.

> We're not even getting close to serious comparisons between the two systems;

You are right, because you are talking about end to end encryption and I am talking about the importance of verifying who you are talking to. Signal fundamentally solves a different problem that PGP is attempting to solve -- and it does so giving up some very strong benefits that PGP brought to the table. Signal is amazing if you don't want onlookers to see your message, not so good if you want to authenticate the sender (unless you go through the extra steps, in which case it is the same cumbersome process as pgp keys.)

In any case, i don't have any more time to spend on this. If you chose to reply I will read it but I am done because think we are going to come to a agreement.

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#46
post #41
post #35

Earlier quoted context omitted.

The only people who agree with you about the need for PGP in serious secure messaging are members of the PGP cheering section. They're an old and venerable social organization dating back to the pre-HMAC CFB-mode cryptography in PGP itself. I have nothing bad to say about their justified and ancient society other than that they are wrong about everything involving cryptography and that they recommend tools that get p…

If someone solved the UI/UX problems with gnupg, and came up with a more elegant method of exchanging/validating keys (or even just an alternate keyserver infrastructure with better properties), wouldn't that solve the problem? Edit: how about a response instead of a downnvote, anonymous detractor?

EDIT: guidelines

As a note, I think there are probably better crypto technologies these days, but none of them do what pgp aimed to do, but rather we have a bunch of smaller tools that do small parts that pgp did. I am not going to send you a singed file over singal, and I think it is silly to have to use a alternative means of sending the file that will either remove the ability for authenticity, or require me to do the authentication dance again with you.

PGP suffers from bad tooling, and further suffers from the relentless onslaught of people who want fancy electron or phone apps that can only do a small % of what pgp would allow.

Final note, I think something better than PGP could exist, but nobody has made it yet. In either case, validating keys will always be a hard problem and any attempt to automate it will result in false sense of security. While end to end encryption will keep on lookers from viewing your communications -- you just might find out one day you are talking directly to the people you were trying to hind your communication from.

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#47
post #41

Earlier quoted context omitted.

If someone solved the UI/UX problems with gnupg, and came up with a more elegant method of exchanging/validating keys (or even just an alternate keyserver infrastructure with better properties), wouldn't that solve the problem? Edit: how about a response instead of a downnvote, anonymous detractor?

EDIT: guidelines As a note, I think there are probably better crypto technologies these days, but none of them do what pgp aimed to do, but rather we have a bunch of smaller tools that do small parts that pgp did. I am not going to send you a singed file over singal, and I think it is silly to have to use a alternative means of sending the file that will either remove the ability for authenticity, or require me to do…

First, the guidelines ask you not to talk about downvotes. You can find out more about that by reading the guidelines.

Secondly, Signal sends files just fine, and does so more securely than GPG. If you don't want to use Signal to do that, you can also use Magic Wormhole, which also works better and is more secure than PGP.

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#48
post #42

Earlier quoted context omitted.

Both of those statements are false. There are clear things wrong with the PGP protocol. PGP predates authenticated encryption (let alone modern AEAD ciphers) and the hacks PGP came up with to authenticate ciphertext resulted both in stripping attacks and, indirectly, in the Efail attack from last year. It was also Signal's linear packet based key format that resulted in the GnuPG/SKS attacks. Signal is a protocol; in…

> Both of those statements are false. Pop on over to wikipeida, you will how wrong you actually are. >> "Signal uses standard cellular mobile numbers as identifiers" >> "The applications include mechanisms by which users can independently verify >> the identity of their messaging correspondents and the integrity of the data >> channel." That is what I described, its trust us first, and maybe verify later if you think…

This is just a series of non-sequiturs.

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#49

I've mostly been able to avoid PGP, but one workflow that I haven't been able to find a decent alternative for it Git commit signing. Does anyone know good alternatives in this space?

Linus himself has expressed his opinion several times that signing every commit is useless. His posts here explain it a bit: http://git.661346.n2.nabble.com/GPG-signing-for-git-commit-t...

Re: Cryptography Dispatches: Hello World, and OpenPGP Is Broken

#50
post #49

I've mostly been able to avoid PGP, but one workflow that I haven't been able to find a decent alternative for it Git commit signing. Does anyone know good alternatives in this space?

Linus himself has expressed his opinion several times that signing every commit is useless. His posts here explain it a bit: http://git.661346.n2.nabble.com/GPG-signing-for-git-commit-t...

Well yes, signing every commit is useless. He did not however, at any point during that exchange, express the idea that commit signing is a useless activity. And that is what I was referring to.

Currently Git seems to be very much integrated with GnuPG and the same goes for GitHub's UX sprinkles over the signing feature. That is what I'd like a decent alternative to.

I considered using OpenBSD's signify but it does not integrate as nicely as GnuPG signing so I'd basically be rolling my own mechanism (which is fine I guess, but feels subpar)

Post reply on HN