Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

121–130 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#121
post #95

Earlier quoted context omitted.

My high school friends and I settled for using Gain and Pidgin to enable the "secure" icon. :)

Been a hot minute since I've thought about Gaim. Thanks for the memories.

Yep, I meant Gaim. Damn you, autocorrect!

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#122

Earlier quoted context omitted.

Any signatory to the Wassenaar Arrangement, which includes the entirety of North America, Europe (including Russia), Australia, India, and Pacific Asia (minus China) must consider cryptographic technologies to be munitions for the purposes of export. Now, these restrictions have been considerably loosened to the point that the export isn't really controlled, but international law still considers it a munition. The US…

I used to be involved in building and shipping research robots (from Canada) and I remember we ran into this a few times with a bog-standard industrial wifi radio that for some reason was under ITAR. Interestingly, the manufacturer of the radio was set up to ship it directly to our customer, we just couldn't integrate it into their robot and ship it from our facility. So they had to put on the radio themselves. The w…

Ah yes...the efficiencies never stop coming when you forced to skirt government mandates about tech they know almost nothing about.

I have war stories for days about all times companies I worked for had to have customers pull DLLs from 3rd party sites in order to comply with completely political mandates.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#123
post #7

Why even bother at this point? PGP encryption in email is... not a good way to do secure communication.

For one, it works.

And if it doesn't work, you're doing it wrong. Or maybe never figured it out well enough to even try in the first place.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#124
post #112

Earlier quoted context omitted.

What is a good non-email use case for the PGP format?

Any usecase forwhich no specialized solution already exists. Source code signatures and Apt/RPM packages are good examples of this.

What does OpenPGP bring there? At least GnuPG has the benefit of being a tool that's present on many system and which is capable of verifying signatures.

If you're not using GnuPG, you can pick any format you want! What does OpenPGP add? Everything I can think of is a negative.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#125
post #8

I do think there ought to be a way to do good cryptography in email. Email is not going away anytime soon, so giving up on it as a legitimate place where cryptography is needed seems too ivory tower for me. The “dead simple solution” is to just run the Signal protocol over SMTP, although I’m sure it’s possible there is a better design if you were to think about the specifics.

> The “dead simple solution” is to just run the Signal protocol over SMTP

I'm pretty sure the dead simple solution is to either use SMTP or Signal and not a frankenstein's monster of both.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#126
post #23

Credit to the people that wrote and maintained bugzilla, both as software and this particular instance. It's still ticking, much longer than (I assume) they planned it to.

My opinion for 20 years has been that Atlassian JIRA would have been stillborn if somebody had added a blue and white CSS theme for Bugzilla.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#127
post #98

Wonderful. What an amazing amount of work to implement a terrible idea. See https://latacora.micro.blog/2019/07/16/the-pgp-problem.html for why we shouldn't be using PGP in 2020.

Gee, this anti-PGP rant showed up 3 times so far in this thread. I think that justifies a link to my critique:

* https://articles.59.ca/doku.php?id=pgpfan:tpp

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#128
post #110
post #99

Earlier quoted context omitted.

The OpenPGP community would do more for security if they listened to serious cryptographers and began recommending better solutions. See https://latacora.micro.blog/2019/07/16/the-pgp-problem.html for more on that. And it isn't hard to find lots and lots of cryptographers agreeing with the thesis.

People in this industry use OpenPGP because it's flexible and amendable to almost any usecase you can think of. "Better solutions" are usually indeed better but are also so specialized for their purpose to the point that they can't be easily used for any other purpose. OpenPGP is used to secure everything from simple messages and email to authenticating OS updates for most servers today. Should they use something mor…

OpenPGP is used to secure everything from simple messages and email to authenticating OS updates for most servers today.

And for MOST of the places that it is used, it gets screwed up in some way that makes it not as secure as the people using it thought that it was.

Stop and think carefully about that statement. And repeat it to every person you meet who thinks that they are solving their problems with OpenPGP.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#129
"How much do you trust the owner of this key to sign other keys properly?

* I don't know

* I do NOT trust

* I trust marginally

* I trust fully

* I trust ultimately"

This is a real pop-up I got the last time I tried to use PGP with Thunderbird.

If people still get regular pop-ups like these, I don't think PGP will ever be popular.

They might have switched to PEP (pretty easy privacy) that uses TOFU (trust-on-first-use) so maybe this is thing of the past, but I don't know.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#130
post #95

Earlier quoted context omitted.

My high school friends and I settled for using Gain and Pidgin to enable the "secure" icon. :)

Been a hot minute since I've thought about Gaim. Thanks for the memories.

Gaim is just Pidgin's original name.
Post reply on HN