Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

181–190 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#181
post #58

Earlier quoted context omitted.

https://gitlab.gnome.org/GNOME/gtk/-/issues/233 16 years and still pending! All bets are off for this dark horse

It has been 21 years since people asked to have SRV DNS resource record support in Mozilla. * http://jdebp.uk./FGA/dns-srv-record-use-by-clients.html

I’m thinking that they might implement HTTPS and SVCB records, once standardized:

https://tools.ietf.org/html/draft-ietf-dnsop-svcb-https-01

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#182

Earlier quoted context omitted.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

The US is all about selective enforcement, and the undesirable hacker type and their unpleasant "cryptography" is likely a higher priority for munitions enforcement than an irritable white guy with an AR-15 at the supermarket, because only one of them actually threatens the status quo.

Well, not anymore as it seems. But the hacker type might now share common interests with the AR-15 guy.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#183

> For reasons associated with U.S. export restrictions, no cryptographic security of any kind is likely to be included in the original sources https://bugzilla.mozilla.org/show_bug.cgi?id=22687#c1 Creepiest thing with seeing this ticket (again?) is noticing that the first comment is about that is used to be illegal to write anything with cryptographic security in the US and sell/give it to the outside world. https://…

Any signatory to the Wassenaar Arrangement, which includes the entirety of North America, Europe (including Russia), Australia, India, and Pacific Asia (minus China) must consider cryptographic technologies to be munitions for the purposes of export. Now, these restrictions have been considerably loosened to the point that the export isn't really controlled, but international law still considers it a munition. The US…

Is establishing a HTTPS connection internationally exporting a munition, using a munition, or none of the above?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#184
post #175

I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…

I find this kind of arguments ridiculous. Sure PGP is not perfect in all cases, but advocating not using it at all is like throwing away the baby with the bath water. And personally, I think the points made it the linked article are weak.

Yeah. PGP doesn’t offer forward secrecy. Solution? Use Age!! which also has no forward secrecy!

Apps like ProtonMail or Tutanota may have an impact on encrypted email. If both sides use ProtonMail, communication is end to end secure. That’s also the case with encrypted messaging. In both cases, copying outside an incompatible platform may be insecure. At least, email address is more private than phone number.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#185

Earlier quoted context omitted.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

The US is all about selective enforcement, and the undesirable hacker type and their unpleasant "cryptography" is likely a higher priority for munitions enforcement than an irritable white guy with an AR-15 at the supermarket, because only one of them actually threatens the status quo.

I think the important word here is "white"

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#186
post #23

Credit to the people that wrote and maintained bugzilla, both as software and this particular instance. It's still ticking, much longer than (I assume) they planned it to.

My opinion for 20 years has been that Atlassian JIRA would have been stillborn if somebody had added a blue and white CSS theme for Bugzilla.

No no no you don't understand, the end users NEED drag and drop (and loading indicators, and slooow and heavy pages to admire those indicators).

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#187

Earlier quoted context omitted.

My high school friends and I settled for using Gain and Pidgin to enable the "secure" icon. :)

Ah, the good old days when I could just plug my IM services into one desktop app. I miss those days very much. Now I use three Electron apps on a typical work day.

Matrix bridges do that for me today! Currently using IRC and Telegram bridges, thinking about adding Slack.

Sadly, Electron-based Element is still the best Matrix client by far.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#188
post #186

Earlier quoted context omitted.

My opinion for 20 years has been that Atlassian JIRA would have been stillborn if somebody had added a blue and white CSS theme for Bugzilla.

No no no you don't understand, the end users NEED drag and drop (and loading indicators, and slooow and heavy pages to admire those indicators).

> the end users NEED drag and drop

Ummm... they do.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#189
post #160

I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…

Autocrypt is the middle ground Thunderbird should have implemented (and which Enigmail used to offer). Email is here to stay, so encryption by default won't happen as long as the PGP standard is used as designed (trust levels and all). Autocrypt improves all that horrible UX, including secure key transfer or rotation, where you can keep doing your own key management if you wish, but you have to do nothing more than e…

From what I've read, PGP for Thunderbird is just a first step. My guess is that they chose the easiest/quickest path for first implementation, but I think we'll see more facilitation of encrypted email in TBird in time.

This makes sense to me. I've been trying to get friends, family and colleagues to encrypt email (hell, even signing would be a step!) for about 3 decades, now, and have basically thrown in the towel. So anything that affords a small toe-hold to begin the painful process of building the necessary network effects for the idea of encrypted email to gain traction is a good thing.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#190

Earlier quoted context omitted.

Isn't the "dead simple solution": 1. Write the message. 2. Encrypt the message. 3. Paste the encrypted message into the email client. Your odds of accidentally sending a message in the clear are zero.

And now to read and reply to it, someone has to copy it from the email client, decrypt it, edit their replies in inline, re-encrypt it, and paste it in. As the number of people on the email chain approaches 2, the chance of someone accidentally copying+pasting the entire email chain decrypted into a reply reaches shockingly high levels. A painful manual process where the simpler slightly-less painful path works, but…

> As the number of people on the email chain approaches 2, the chance of someone accidentally copying+pasting the entire email chain decrypted into a reply reaches shockingly high levels.

Heck, people (myself included) regularly mess up Reply and Reply All :-)

Post reply on HN