The reality of the situation is that you can't remove the human factor from security. So someone copying your email to someone else is a human problem that can't be fixed - someone could just as easily photograph the screen. The reality is email will continue to be used, and there is a use case for being able to send an email securely to another person. EFail was pretty bad, but only affected HTML email. Having a mod…
Opmsg – A GPG Alternative
41–50 of 100 posts
Re: Opmsg – A GPG Alternative
#42I am not qualified to review how it implements forward security, for instance. But this shares a lot of the problems that GPG has. It relies on existing mail standards, so it leaks metadata all over the place, and security can easily be defeated by "accidentally replying without encrypting." It's configurable -- every choice you have to make is a chance to make the wrong one. It implements RSA, which nobody should be…
This screenshot of an Ars Technica journalist with Phil Zimmerman, PGP author (yes, not the same as GPG), is very telling: https://arstechnica.com/information-technology/2016/12/op-ed...
It could be that Phil has a policy of not storing private keys on his iPhone or something. Is that so unusual?
Anyways, maybe you're privy to context that I'm missing.
Re: Opmsg – A GPG Alternative
#43I am not qualified to review how it implements forward security, for instance. But this shares a lot of the problems that GPG has. It relies on existing mail standards, so it leaks metadata all over the place, and security can easily be defeated by "accidentally replying without encrypting." It's configurable -- every choice you have to make is a chance to make the wrong one. It implements RSA, which nobody should be…
> It relies on existing mail standards This is a feature, not a bug. Nobody actually wants to rely on a single entity (for or non-profit) for their communication. Nobody wants to be stuck in crappy Electron and mobile clients. I had some hope that Matrix may be able to alleviate those concerns and provide a modern, federated chat solutions. Unfortunately their quality of implementation seems to be rather low with slo…
Re: Opmsg – A GPG Alternative
#44Earlier quoted context omitted.
> It relies on existing mail standards This is a feature, not a bug. Nobody actually wants to rely on a single entity (for or non-profit) for their communication. Nobody wants to be stuck in crappy Electron and mobile clients. I had some hope that Matrix may be able to alleviate those concerns and provide a modern, federated chat solutions. Unfortunately their quality of implementation seems to be rather low with slo…
Most people really don't care. They use Whatsapp because that's where their friends are and they will move to whatever their friends start using next.
Re: Opmsg – A GPG Alternative
#45Earlier quoted context omitted.
This screenshot of an Ars Technica journalist with Phil Zimmerman, PGP author (yes, not the same as GPG), is very telling: https://arstechnica.com/information-technology/2016/12/op-ed...
I'm not sure what you're implying, but without context, the screenshot is meaningless. It could be that Phil has a policy of not storing private keys on his iPhone or something. Is that so unusual? Anyways, maybe you're privy to context that I'm missing.
Re: Opmsg – A GPG Alternative
#46I am not qualified to review how it implements forward security, for instance. But this shares a lot of the problems that GPG has. It relies on existing mail standards, so it leaks metadata all over the place, and security can easily be defeated by "accidentally replying without encrypting." It's configurable -- every choice you have to make is a chance to make the wrong one. It implements RSA, which nobody should be…
There are automated solutions for this in existence for many-many years.
Re: Opmsg – A GPG Alternative
#47Earlier quoted context omitted.
This screenshot of an Ars Technica journalist with Phil Zimmerman, PGP author (yes, not the same as GPG), is very telling: https://arstechnica.com/information-technology/2016/12/op-ed...
I'm not sure what you're implying, but without context, the screenshot is meaningless. It could be that Phil has a policy of not storing private keys on his iPhone or something. Is that so unusual? Anyways, maybe you're privy to context that I'm missing.
Re: Opmsg – A GPG Alternative
#48I think a perhaps unclear part of the recent post "The PGP Problem" is that PGP is bad for email . If you don't use it for email, I don't see it as really a problem. Unless, maybe, you are a reporter or otherwise not clear on the principles behind using something like GPG. I think personally that the point about all the discussion is that for laypeople PGP and email is just too complicated (even for myself as a progr…
My understanding is quite different. Email is inherently insecure and there is nothing you can do about it. PGP is insecure for everything else as well The Latacora article was eye-opening for me on the email problem - quite simply if I send an encrypted mail to a friend / collegue - which I intend them to read, and they read it and quote it to someone else in plain text then that's it - my plaintext and my cipher ar…
Wait a minute. I may have to read the Latacora article again but if we are dealing with ciphers where having a plaintext attack reveals the key, I think we're in a lot bigger trouble than I ever imagined. To be blunt I don't really believe it and it would take some explanation to convince me it's true.
Edit: OK, I think I see the problem. I believe the quote in the article is discussing the fact that the user happily quotes a message and doesn't re-encrypt it, meaning that you have accidentally leaked the plain text -- not that they key is known. So I think they are arguing that we should write apps so that it is impossible to copy the plaintext.
Re: Opmsg – A GPG Alternative
#49I think a perhaps unclear part of the recent post "The PGP Problem" is that PGP is bad for email . If you don't use it for email, I don't see it as really a problem. Unless, maybe, you are a reporter or otherwise not clear on the principles behind using something like GPG. I think personally that the point about all the discussion is that for laypeople PGP and email is just too complicated (even for myself as a progr…
My understanding is quite different. Email is inherently insecure and there is nothing you can do about it. PGP is insecure for everything else as well The Latacora article was eye-opening for me on the email problem - quite simply if I send an encrypted mail to a friend / collegue - which I intend them to read, and they read it and quote it to someone else in plain text then that's it - my plaintext and my cipher ar…
Re: Opmsg – A GPG Alternative
#50Earlier quoted context omitted.
I'm not sure what you're implying, but without context, the screenshot is meaningless. It could be that Phil has a policy of not storing private keys on his iPhone or something. Is that so unusual? Anyways, maybe you're privy to context that I'm missing.
I would say the implication is that PGP is useless for general secure communications purposes. You can be secure with it when you have very specific needs and have knowledgeable contacts, but it doesn't solve the need for communications privacy that most people have.