Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

91–100 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#91

I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…

That would make sense for people who consider privacy as single most important measure for communication system. That is not true for everybody. The advantage of OpenPGP is that it does not break any existing advantages of e-mail (except perhaps simplicity) so it is unequivocally better than unencrypted e-mail, while other protocols may have better encryption / privacy, but are worse in other measures.

For me, open-standard-ness and federated-ness are two measures that i consider even more important than cryptographic security. So communication protocol that does not satisfy either of these have little value to me, i would rather use e-mail.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#94

Ignorant question time, will this mean native support for email services like proton mail?

protonmail is different in that they have their own client/server protocol and you need something like their protonmail-bridge to interface with them over IMAP (which is only for paid accounts and does not depend on this feature).

It makes it smoother to send and receive e-mails signed/encrypted with PGP.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#95

Earlier quoted context omitted.

at least you had a friend to email! I couldn't get any of my friends to do it. "Man we can encrypt our emails." "But why..." "It'd be cool" "This seems hard." "Come on, exchange keys with me." "I don't want to make one."

My high school friends and I settled for using Gain and Pidgin to enable the "secure" icon. :)

Been a hot minute since I've thought about Gaim. Thanks for the memories.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#96
post #86
post #85

Earlier quoted context omitted.

(Open)PGP is first and foremost a flexible packet format That makes an even better case that PGP is not much of a modern secure system generally, rather than it just being bad for secure email.

Because packet formats are bad? I don't understand what you're trying to say here.

Because a flexible 'format' or 'model' or whatever with which you can construct insecure systems or (hypothetically) secure systems, is not really useful, it ends up being inherently insecure.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#97
post #53

Earlier quoted context omitted.

Signal is great as an all in one solution if encrypted messaging is a hobby. It is also very good for mobile and encrypted occasional messages. If you try to actually build a secure environment within a group that tries to maximize security while getting real work done you find you want to be encrypted by default at least with each other. Signal is pretty suboptimal for heavy volumes of messages. If you and I have th…

So you're saying that if you're building a professional secure environment, you don't need forward secrecy and it's ok to leak metadata? This doesn't make sense to me. The US gov't kills people based on metadata: https://ssd.eff.org/en/module/why-metadata-matters It's not possible to make email secure, the flaws are on the protocol level. To fix it, you would need to change it until it is no longer email.

If you're building a professional secure environment, forward secrecy is a tradeoff that you need to tune (and OpenPGP gives you the tools for doing so, viz. subkeys and expiration), you absolutely need federation, and identifying contacts by phone numbers (as Signal does) is a zillion times worse than leaking email headers.

It's not possible to make Signal secure, the flaws are on the protocol level. To fix it, you would need to change it until it is no longer Signal.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#99
post #83
post #76

Earlier quoted context omitted.

> GnuPG is more of a CLI "library" to interface with it It abjectly fails at that. It's just awful to interface with.

Agreed. It has been long overdue that alternative OpenPGP implementations exist that try to address some of the peculiarities of GnuPG -- most of which are [still] there because its founder wants to preserve compatibility at all costs to support some of its long-term institutional users. And, yes, dealing with these peculiarities should not the responsibility of end users, but of further abstraction layers built on t…

The OpenPGP community would do more for security if they listened to serious cryptographers and began recommending better solutions.

See https://latacora.micro.blog/2019/07/16/the-pgp-problem.html for more on that. And it isn't hard to find lots and lots of cryptographers agreeing with the thesis.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#100

Earlier quoted context omitted.

There's as many developers working on it now as there were when it was a part of Mozilla.

Are they still paid by Mozilla, though?

They are not paid by Mozilla, but there are still paid contributors.
Post reply on HN