Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

151–160 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#151

Is this the longest time between request/bug and fix?

If it does have that title, there are other bugs that are almost as old in Thunderbird and still open, so it might not hold the record for long if someone gets around to fixing any of those.

For example, bug 41929 [1] is only 6 months younger. Briefly, you cannot have two different IMAP accounts in Thunderbird that have the same username and host but different ports.

[1] https://bugzilla.mozilla.org/show_bug.cgi?id=41929

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#152
post #117
post #87

Earlier quoted context omitted.

If you believe in abolishing hierarchy and institutions where they have no legitimacy, _all_ you are left with is communication, community, and open standardization as practiced in anarchist bodies such as the IETF.

> anarchist bodies such as the IETF That's an incredibly... unconventional read on the IETF.

Not really. I know very little about both anarchy and the IETF, but voluntary organisation (as in opposed to wage slavery) and a democratic governing of the group is very much in line with many anarchistic schools.

Edit: language fixes. English is not my language of choice for discussing things like this...

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#153
post #130
post #95

Earlier quoted context omitted.

Been a hot minute since I've thought about Gaim. Thanks for the memories.

Gaim is just Pidgin's original name.

I assume he first used it when it was called Gaim, so he has stronger memories associated with that name than with Pidgin.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#154
post #122

Earlier quoted context omitted.

I used to be involved in building and shipping research robots (from Canada) and I remember we ran into this a few times with a bog-standard industrial wifi radio that for some reason was under ITAR. Interestingly, the manufacturer of the radio was set up to ship it directly to our customer, we just couldn't integrate it into their robot and ship it from our facility. So they had to put on the radio themselves. The w…

Ah yes...the efficiencies never stop coming when you forced to skirt government mandates about tech they know almost nothing about. I have war stories for days about all times companies I worked for had to have customers pull DLLs from 3rd party sites in order to comply with completely political mandates.

I had a professor tell me a story about a small tech company he worked at way back when, where they actually smuggled their POS terminal system by fishing boat out of the US and into Canada to sell outside the US to get around export controls even though the algorithms they used were widely known.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#155

Earlier quoted context omitted.

For those that don't click through, it repeats what is a fairly cogent argument. If cryptography is classified as a munition, then there should be legal room to argue we have the right to it as provided by the 2nd amendment.

Congrats, you don't get encrypted because you're not a member of a tightly regulated militia. Sarcasm aside, the only way to make sure people get encryption is to make it impossible to restrict the technology. That's how encryption ended up spreading. You don't put disruptive tech on every computer on the planet by waiting for permission.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#156

I remember back in the 90s exchanging PGP keys with my roommate to exchange encrypted emails. It was supposed to be so easy. Just 12 simple steps. Every time.

at least you had a friend to email! I couldn't get any of my friends to do it. "Man we can encrypt our emails." "But why..." "It'd be cool" "This seems hard." "Come on, exchange keys with me." "I don't want to make one."

[deleted]

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#157
post #73

Earlier quoted context omitted.

I understand that PGP doesn't have to be used with email. That is why I haven't commented on PGP, I'm saying that I think encrypted email is a bad idea, regardless of whether you use PGP or something else. We're posting in a thread about Thunderbird, an e-mail client :) I agree that one great weakness of Signal is its centralization, and that decentralization is a great strength of email. For a decentralized encrypte…

For future reference, statements like this: > I used to love [A], but I now think [B] is a bad idea. will lead many people to think that you consider A and B to be essentially the same thing. In the specific case of PGP and encrypted email, this is a category error: you are implying (perhaps unintentionally) that PGP’s only use is for encrypted email.

Dude, come on...

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#158
post #122

Earlier quoted context omitted.

I used to be involved in building and shipping research robots (from Canada) and I remember we ran into this a few times with a bog-standard industrial wifi radio that for some reason was under ITAR. Interestingly, the manufacturer of the radio was set up to ship it directly to our customer, we just couldn't integrate it into their robot and ship it from our facility. So they had to put on the radio themselves. The w…

Ah yes...the efficiencies never stop coming when you forced to skirt government mandates about tech they know almost nothing about. I have war stories for days about all times companies I worked for had to have customers pull DLLs from 3rd party sites in order to comply with completely political mandates.

It'll be even more efficient soon, when the backdoors come.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#159

I remember back in the 90s exchanging PGP keys with my roommate to exchange encrypted emails. It was supposed to be so easy. Just 12 simple steps. Every time.

PGPs trust levels are what made PGP never take off: even laypersons could see this is theater, not security.

For reasons unclear to me Thunderbird chose not to go with something like autocrypt.org, but stick with standard PGP and implement parts of their attempt to simplify, which isn't nearly enough to get regular users on board, never mind implement things like forward security, which autocrypt does.

A missed chance from Mozilla, secure email would fit in well with their mission.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#160

I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…

Autocrypt is the middle ground Thunderbird should have implemented (and which Enigmail used to offer). Email is here to stay, so encryption by default won't happen as long as the PGP standard is used as designed (trust levels and all). Autocrypt improves all that horrible UX, including secure key transfer or rotation, where you can keep doing your own key management if you wish, but you have to do nothing more than enable Autocrypt if you don't. It's a mystery why Mozilla didn't push this, seems a perfect fit for them to empower regular web users.
Post reply on HN