Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

231–240 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#231
post #109

Earlier quoted context omitted.

Relevant xkcd: https://xkcd.com/504/

For those that don't click through, it repeats what is a fairly cogent argument. If cryptography is classified as a munition, then there should be legal room to argue we have the right to it as provided by the 2nd amendment.

The the 2nd amendment is irrelevant here. That amendment only applies within the US and this is about export controls. Pretty much every US constitutional protection disintegrates once the issue becomes international.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#232

Earlier quoted context omitted.

Side note: don’t call the countries in the European Union “states”. They’re sovereign countries that have committed themselves through treaties to the Union, not a US like government body

Languages are strange in very different ways. The Italian word for country is "stato". How do we translate state as in "NY is a state of the USA"? Again "stato". We have "nazione" for nations but really nothing for countries. We do say "paesi esteri" for "foreign countries" but that's almost the only occurrence with that meaning. A "paese" is a town, so nobody will ever say that Germany or France are a "paese".

Actually, "paese" is the normal translation for country (optionally with capital "P" if one wants to avoid ambiguities with the "town" meaning)

> nobody will ever say that Germany or France are a "paese"

Google lists > 200.000 results for "la Germania è un paese".

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#233
post #196

Earlier quoted context omitted.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…

Thanks for the context, that joke about the 2nd amendment's widening scope had indeed gone over my head.

> You need to broaden your news sources

To be fully honest, I don't think I "need" to anything. My life doesn't revolve around having an accurate impression of the US. The image your country spreads of itself is one of loud angry lefties on the coasts and gun wielding red necks in-between. I'm sure that reality is very different, but don't blame me for the bad country marketing :-)

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#234
post #128
post #110

Earlier quoted context omitted.

People in this industry use OpenPGP because it's flexible and amendable to almost any usecase you can think of. "Better solutions" are usually indeed better but are also so specialized for their purpose to the point that they can't be easily used for any other purpose. OpenPGP is used to secure everything from simple messages and email to authenticating OS updates for most servers today. Should they use something mor…

OpenPGP is used to secure everything from simple messages and email to authenticating OS updates for most servers today. And for MOST of the places that it is used, it gets screwed up in some way that makes it not as secure as the people using it thought that it was. Stop and think carefully about that statement. And repeat it to every person you meet who thinks that they are solving their problems with OpenPGP.

What do you mean by PGP "not [being] as secure as the people using it thought that it was"? Can you mention something specific?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#235

Earlier quoted context omitted.

Flexibility in cryptography is often very bad and opens doors to downgrade attacks or things like JWT’s alg:none issues. https://www.imperialviolet.org/2016/05/16/agility.html “Have one joint, and keep it well oiled.”

The linked article is all about protecting data in flight like in the TLS case. PGP is all about protecting data at rest. The two applications are fundamentally different.

I think you're misunderstanding the general complaint or maybe not the complaint but how general, rather than specific it is.

At the top of the thread someone says 'PGP has all this ancient cruft and also isn't good for email/email is maybe unsecurable anyway'. The PGP-enthusiast response to that is 'No problem! You see, PGP is so flexible, you can build anything out of it, including maybe an actually-secure system of some sort'.

This is a fundamentally inadequate response and we've realized it's inadequate and don't really design secure systems like that anymore. In fact, this class of concern has permeated almost all aspects of contemporary software systems design rather than being something narrowly limited to 'crypto algo agility is bad'. Here's an example/illustrative timeline that doesn't have anything to do with 'data at rest'.

1998 Netscape: Behold our cross-platform, cross-language super-toolkit for building super-extensible Enterprise Groupware apps. Also one of them is a web browser!

2015 Mozilla: [belated forehead slap] This is a terrible way to architect a web browser that has any hope of offering end-user security.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#236
post #235

Earlier quoted context omitted.

The linked article is all about protecting data in flight like in the TLS case. PGP is all about protecting data at rest. The two applications are fundamentally different.

I think you're misunderstanding the general complaint or maybe not the complaint but how general, rather than specific it is. At the top of the thread someone says 'PGP has all this ancient cruft and also isn't good for email/email is maybe unsecurable anyway'. The PGP-enthusiast response to that is 'No problem! You see, PGP is so flexible, you can build anything out of it, including maybe an actually-secure system o…

How do you do a downgrade attack on, say, an encrypted backup?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#237
post #235

Earlier quoted context omitted.

I think you're misunderstanding the general complaint or maybe not the complaint but how general, rather than specific it is. At the top of the thread someone says 'PGP has all this ancient cruft and also isn't good for email/email is maybe unsecurable anyway'. The PGP-enthusiast response to that is 'No problem! You see, PGP is so flexible, you can build anything out of it, including maybe an actually-secure system o…

How do you do a downgrade attack on, say, an encrypted backup?

I guess I don't understand how that's a response to anything I've written in this thread.

Edit: I'll expand the quote from the original thing a bit if it helps:

(Open)PGP is first and foremost a flexible packet format (and other specs), and GnuPG is more of a CLI "library" to interface with it -- all of it. You can build something that hides metadata, you can have forward secrecy, and encryption always-on by default with PGP (and GnuPG). You can use it for whatever trust model you want, neither OpenPGP (the specs) nor GnuPG prescribe a certain model. It provides building blocks.

This is a huge 'nope'. It's, by this point, an uncontroversial, well-understood nope. A known-nope, if you will! The only people who don't seem to think so are PGP people and that, in itself, is rather telling.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#238
post #159

Earlier quoted context omitted.

PGPs trust levels are what made PGP never take off: even laypersons could see this is theater, not security. For reasons unclear to me Thunderbird chose not to go with something like autocrypt.org, but stick with standard PGP and implement parts of their attempt to simplify, which isn't nearly enough to get regular users on board, never mind implement things like forward security, which autocrypt does. A missed chanc…

There is an autocrypt plugin for Thunderbird: * https://addons.thunderbird.net/en-US/thunderbird/addon/autoc... Now that most SMTP connections are encrypted with STARTTLS on the wire, autocrypt is not that valuable. At an email server autocrypt can be trivially man in the middled with just a simple script. It ends up being just another encrypted messaging solution that skips the hard but crucial problem of identity.…

I know, and I use it. It however wont support TB 78.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#239
post #226

Earlier quoted context omitted.

U.S. states are sovereign states, just like EU states are. They United States government itself is also sovereign, in a sense that the EU government itself may or may not be. (Most) Americans live under two sovereigns: their state and the U.S.

Maybe so, but then we need to come up with more words. As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.)

> As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.)

Which article or amendment of the U.S. Constitution forbids a state to leave without permission of the U.S.?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#240

Earlier quoted context omitted.

For those that don't click through, it repeats what is a fairly cogent argument. If cryptography is classified as a munition, then there should be legal room to argue we have the right to it as provided by the 2nd amendment.

The the 2nd amendment is irrelevant here. That amendment only applies within the US and this is about export controls. Pretty much every US constitutional protection disintegrates once the issue becomes international.

The joke is pointed towards legislation that would make encryption illegal in the US.
Post reply on HN