Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

171–180 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#171

Earlier quoted context omitted.

Any signatory to the Wassenaar Arrangement, which includes the entirety of North America, Europe (including Russia), Australia, India, and Pacific Asia (minus China) must consider cryptographic technologies to be munitions for the purposes of export. Now, these restrictions have been considerably loosened to the point that the export isn't really controlled, but international law still considers it a munition. The US…

Side note: don’t call the countries in the European Union “states”. They’re sovereign countries that have committed themselves through treaties to the Union, not a US like government body

Country means “sovereign state” - no-one’s suggesting EU member states aren’t sovereign nations in the sense US states aren’t.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#172
Thunderbird has the only calendar I know that has a "multiweek" display as opposed to (well, in addition to) the utterly retarded month view that exists in every other GUI.

We've been doing electronic calendars for how long now? Why are we still using a paradigm from paper based calendars? At the beginning of a month I can see three weeks ahead, but at the end of the month I can see three weeks behind. It frustrates me no end that this is still a thing. It reminds me of the early days of Google maps when they were no better than paper maps, but now we can rotate the map, zoom in and out etc. But calendars are still no better than paper calendars. Apart from the one in Thunderbird.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#173

I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…

Your article seems to focus on individuals. Consider also organisations.

Transport-level security and authentication of email content is a perfectly valid use-case for an organisation when protection against third-party interference is desired. They don't need to worry about forward secrecy, they just need attachments to be transmitted in a legally-compliant manner.

For example each month HR email me my payslip as an encrypted attachment. I decrypt it and save locally. They just have a batch job that encrypts for each user and sends. They don't have to worry about who uses which IM client. They don't need to care if I self-host or use Gmail, because their ligation is simply to keep the information secure in transit.

You are also too keen to support Signal's use of phone numbers as identifiers. That's a design choice, instead of using client-managed identifiers, and makes it unsuitable for organisational use. Whose phone will we use to send the deposition to the court... and who in the court will have a phone with Signal on it? Email by contrast is universal and integrates well into organisational processes without dependency upon individuals.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#174
post #8

I do think there ought to be a way to do good cryptography in email. Email is not going away anytime soon, so giving up on it as a legitimate place where cryptography is needed seems too ivory tower for me. The “dead simple solution” is to just run the Signal protocol over SMTP, although I’m sure it’s possible there is a better design if you were to think about the specifics.

You could run any encrypted protocol on top of SMTP/IMAP; been there, done that; the main issue is you need specialized software on both ends to make it work.

Still, doing so solves the transport and persistence problems you would otherwise have to deal with.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#175

I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…

I find this kind of arguments ridiculous. Sure PGP is not perfect in all cases, but advocating not using it at all is like throwing away the baby with the bath water.

And personally, I think the points made it the linked article are weak.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#176

Earlier quoted context omitted.

at least you had a friend to email! I couldn't get any of my friends to do it. "Man we can encrypt our emails." "But why..." "It'd be cool" "This seems hard." "Come on, exchange keys with me." "I don't want to make one."

My high school friends and I settled for using Gain and Pidgin to enable the "secure" icon. :)

Ah, the good old days when I could just plug my IM services into one desktop app. I miss those days very much.

Now I use three Electron apps on a typical work day.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#177

Earlier quoted context omitted.

Congrats, you don't get encrypted because you're not a member of a tightly regulated militia. Sarcasm aside, the only way to make sure people get encryption is to make it impossible to restrict the technology. That's how encryption ended up spreading. You don't put disruptive tech on every computer on the planet by waiting for permission.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

The US is all about selective enforcement, and the undesirable hacker type and their unpleasant "cryptography" is likely a higher priority for munitions enforcement than an irritable white guy with an AR-15 at the supermarket, because only one of them actually threatens the status quo.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#178

Earlier quoted context omitted.

Backup, archivization, password managers, the list is long. Duplicity has many users: http://duplicity.nongnu.org Pass is also pretty popular on HN: https://www.passwordstore.org Both use GPG.

I use pass and I would switch in a heartbeat to a fork of it that used ssh keys or something similar instead of gpg. For something so amazingly simple and useful, its dependence on the klunky mess that is gpg key management is an anchor that weighs it down.

Key management is a burden in every cryptosystem. I'm using KeePass and can recommend it, it works well.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#179

Never seen a timestamp on the web that said "20 years ago". Wow. Reminds me of a tiny blog post I put up years ago about the future of archaeology. Forgive the silly site title. https://meaninglessdreams.wordpress.com/2014/09/26/156/

Man the last company I worked at had bugs that had been updates going back over 30 years. Kinda surreal looking at bugs that are older than you are.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#180

Earlier quoted context omitted.

Any signatory to the Wassenaar Arrangement, which includes the entirety of North America, Europe (including Russia), Australia, India, and Pacific Asia (minus China) must consider cryptographic technologies to be munitions for the purposes of export. Now, these restrictions have been considerably loosened to the point that the export isn't really controlled, but international law still considers it a munition. The US…

Side note: don’t call the countries in the European Union “states”. They’re sovereign countries that have committed themselves through treaties to the Union, not a US like government body

When we nitpick,

"country" = geographic unit, "state" = political unit.

The United States is itself a state, albeit a federation of smaller states.

Post reply on HN