Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

191–200 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#191
post #93

I'm more impressed that a ticket managed to live on in a tracker for so long without getting lost over the years.

In contrast to ansible issues, which would have changed tracker or repo ~30 times in that time.

Also: No, no, you're wrong. Ansible is not crashing, you're just holding it wrong.

:-p

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#192
post #86
post #85

Earlier quoted context omitted.

(Open)PGP is first and foremost a flexible packet format That makes an even better case that PGP is not much of a modern secure system generally, rather than it just being bad for secure email.

Because packet formats are bad? I don't understand what you're trying to say here.

Because flexibility brings bugs, and bugs in cryptography means breach of security.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#193
post #110

Earlier quoted context omitted.

People in this industry use OpenPGP because it's flexible and amendable to almost any usecase you can think of. "Better solutions" are usually indeed better but are also so specialized for their purpose to the point that they can't be easily used for any other purpose. OpenPGP is used to secure everything from simple messages and email to authenticating OS updates for most servers today. Should they use something mor…

What industry do you mean by "this industry"? Just... computing? I didn't know OpenPGP was used to authenticate OS updates for most servers today. Can you give me a place to find out more about that; are you talking about a specific OS?

It's used to digitally sign software, not encrypting.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#194
post #184
post #175

Earlier quoted context omitted.

I find this kind of arguments ridiculous. Sure PGP is not perfect in all cases, but advocating not using it at all is like throwing away the baby with the bath water. And personally, I think the points made it the linked article are weak.

Yeah. PGP doesn’t offer forward secrecy. Solution? Use Age!! which also has no forward secrecy! Apps like ProtonMail or Tutanota may have an impact on encrypted email. If both sides use ProtonMail, communication is end to end secure. That’s also the case with encrypted messaging. In both cases, copying outside an incompatible platform may be insecure. At least, email address is more private than phone number.

> If both sides use ProtonMail, communication is end to end secure.

If both sides use [the same provider], it's not mail anymore, it's something internal. That is the fundamental issue of ProtonMail/Tutanota/any service provider that pretends to solve end-to-end encryption in email: without standards, it's a proprietary system. Today the only viable path towards easy E2E encryption in email is Autocrypt. AFAIK only Posteo is working towards including it.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#195

> For reasons associated with U.S. export restrictions, no cryptographic security of any kind is likely to be included in the original sources https://bugzilla.mozilla.org/show_bug.cgi?id=22687#c1 Creepiest thing with seeing this ticket (again?) is noticing that the first comment is about that is used to be illegal to write anything with cryptographic security in the US and sell/give it to the outside world. https://…

That's why there were those "illegal" t-shirts with the RSA algorithm printed out in Perl.

But I have a more pragmatic approach. If nuclear launch codes were written out on t-shirts I wouldn't be happy about it either. I think the real problem is ignorance. The US's main role after 1945, and the role of the UN, was and is to prevent another world war. Whether by virtue or by ignorance they have been successful, with the notable exception of a partial world war in the Middle East.

Having said that, the problem is ignorance towards technology and knowledge and resentment towards talent or individual ability. It's more general fear towards things they cannot understand, or rather, things they understand that they cannot subvert. But, I don't like to reduce myself to a protagonist's syndrome and I can more or less understand why the US government does what they do.

The only real node of certainty in the whole equation is that individual freedom is where the line should be drawn. And unfortunately for the obnoxious prescriptive types, any human can invent cryptography on their own whilst living in a cave.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#196

Earlier quoted context omitted.

Congrats, you don't get encrypted because you're not a member of a tightly regulated militia. Sarcasm aside, the only way to make sure people get encryption is to make it impossible to restrict the technology. That's how encryption ended up spreading. You don't put disruptive tech on every computer on the planet by waiting for permission.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia.

Unfortunately SCOTUS has continually widened the scope of 2A over the years.

> as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles

You need to broaden your news sources; this is by no means common, except for perhaps in a few gun-happy states like Texas.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#197
post #93

I'm more impressed that a ticket managed to live on in a tracker for so long without getting lost over the years.

In contrast to ansible issues, which would have changed tracker or repo ~30 times in that time.

Or any other recent repo where issues get "stale" and closed automatically.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#198
post #40

Earlier quoted context omitted.

You build it on SMTP because upgrading clients is easier than doing a clean slate redesign of ubiquitous internet protocols. Presumably we're discussing how an open protocol addition might gain any traction at all over walled garden protocols like Slack -- and in those cases you want to maintain as much compatibility as possible. "Federated SecureEmail 2.0" would be dead-on-arrival, where "Secure Client on top of bog…

>You build it on SMTP because upgrading clients is easier than doing a clean slate redesign of ubiquitous internet protocols. Why not just toss the whole shebang and rebuild it below that layer? Signal Protocol seems to be pretty successful here. >Presumably we're discussing how an open protocol addition might gain any traction at all over walled garden protocols like Slack No, I'm asking how a new open protocol can…

> No, I'm asking how a new open protocol can be built on top of email in a way that maintains strong backwards compatibility while offering strong security guarantees, like end-to-end encryption. I don't think it's possible.

That's exactly what Autocrypt is doing. They're still at level 1, ie opportunistic encryption: try to encrypt if possible, default to plain-text if not. That's 100% backwards-compatible.

What we all want is a system where we are sure that messages can't be sent in plaintext. The only way this can happen is if MTAs actually read messages and check if encryption is applied; if not, reject it. That's something that can happen but by definition it can't be backwards-compatible.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#199
post #196

Earlier quoted context omitted.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…

> You need to broaden your news sources; this is by no means common, except for perhaps in a few gun-happy states like Texas.

The only places I have seen images like that is on sites like Reddit with some sort of 'Murica' text next to it, but it is still pretty insane that this sort of thing can be shrugged off as "this is by no means common, except for perhaps in a few gun-happy states like Texas.".

To be clear, I am not criticising you personally, but isn't it crazy that there are places in the US where people go to the cinema or super market in tactical gear and rifles and that the people around them don't run away screaming?

Post reply on HN