Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

241–250 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#241

I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…

Does Signal still require you to use your phone number to use it?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#242
post #196

Earlier quoted context omitted.

I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".

It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…

I have a different perspective. I think that the scope of the 2nd amendment has narrowed over the years. In 1776, private citizens owned every kind and sort of weapon used by the military. Ordinary people owned cannons, were instructed to put cannons on their private ships to defend against pirates, and owned the same sorts of muskets used by the army. The modern equivalent would be buying tanks at Walmart for cash and not registering the purchase nor requiring a background check.

By the way, the archaic meaning of "regulated" means "properly disciplined and drilled". It did not refer to control or supervision by a state.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#243

Earlier quoted context omitted.

A slightly more realistic "dead simple solution" might be for mail clients to extend their OpenPGP support to include Autocrypt[0] which would allow users to gain some of the advantages of OpenPGP without having to understand any of the details. [0] https://autocrypt.org/

Interesting. In my opinion, this should also contain provisions for storing the private key password-encrypted on the IMAP server.

I think that's what the Autocrypt Setup Message is for:

https://autocrypt.org/level1.html#autocrypt-setup-message

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#244
post #237

Earlier quoted context omitted.

How do you do a downgrade attack on, say, an encrypted backup?

I guess I don't understand how that's a response to anything I've written in this thread. Edit: I'll expand the quote from the original thing a bit if it helps: (Open)PGP is first and foremost a flexible packet format (and other specs), and GnuPG is more of a CLI "library" to interface with it -- all of it. You can build something that hides metadata, you can have forward secrecy, and encryption always-on by default…

You can't just "Nope" this issue. You need to come up with some sort of rational argument. The PGP people have been dealing with the data at rest issue since forever. It is a bit presumptuous to just write off all that acquired wisdom without reason.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#245
post #239

Earlier quoted context omitted.

Maybe so, but then we need to come up with more words. As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.)

> As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.) Which article or amendment of the U.S. Constitution forbids a state to leave without permission of the U.S.?

https://en.m.wikipedia.org/wiki/Secession_in_the_United_Stat...

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#246
post #237

Earlier quoted context omitted.

I guess I don't understand how that's a response to anything I've written in this thread. Edit: I'll expand the quote from the original thing a bit if it helps: (Open)PGP is first and foremost a flexible packet format (and other specs), and GnuPG is more of a CLI "library" to interface with it -- all of it. You can build something that hides metadata, you can have forward secrecy, and encryption always-on by default…

You can't just "Nope" this issue. You need to come up with some sort of rational argument. The PGP people have been dealing with the data at rest issue since forever. It is a bit presumptuous to just write off all that acquired wisdom without reason.

I have come up with a rational argument, you just refuse to address it at all. Your argument boils down to 'the PGP people are smarter than everyone else' which I think isn't really even a rational argument.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#247
post #234
post #128

Earlier quoted context omitted.

OpenPGP is used to secure everything from simple messages and email to authenticating OS updates for most servers today. And for MOST of the places that it is used, it gets screwed up in some way that makes it not as secure as the people using it thought that it was. Stop and think carefully about that statement. And repeat it to every person you meet who thinks that they are solving their problems with OpenPGP.

What do you mean by PGP "not [being] as secure as the people using it thought that it was"? Can you mention something specific?

Here is something specific.

Due to the complexity of the PGP system, there are a plethora of downgrade attacks. Where something that was supposed to be at one level of security can be tricked into doing something much less secure. See https://twitter.com/xmppwocky/status/1291144278953955328, https://mailarchive.ietf.org/arch/msg/openpgp/JLn7sL6TqikUf-..., and https://www.eff.org/deeplinks/2018/05/pgp-and-efail-frequent... for three different examples of such attacks against PGP in recent years.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#248

Earlier quoted context omitted.

I use pass and I would switch in a heartbeat to a fork of it that used ssh keys or something similar instead of gpg. For something so amazingly simple and useful, its dependence on the klunky mess that is gpg key management is an anchor that weighs it down.

Key management is a burden in every cryptosystem. I'm using KeePass and can recommend it, it works well.

Would you know if it failed?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#249
post #247
post #234

Earlier quoted context omitted.

What do you mean by PGP "not [being] as secure as the people using it thought that it was"? Can you mention something specific?

Here is something specific. Due to the complexity of the PGP system, there are a plethora of downgrade attacks. Where something that was supposed to be at one level of security can be tricked into doing something much less secure. See https://twitter.com/xmppwocky/status/1291144278953955328 , https://mailarchive.ietf.org/arch/msg/openpgp/JLn7sL6TqikUf-... , and https://www.eff.org/deeplinks/2018/05/pgp-and-efail-freq…

The first one appears to be some sort of joke.

The second one is just yet another person discovering that the MDC check can be stripped off a message.

The third one seems to be just EFAIL which is not a downgrade or any attack really against PGP.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#250
post #196

Earlier quoted context omitted.

It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…

Texas isn't like that either. I've lived in Texas for almost a decade and I've never seen someone open carrying a long rifle at the supermarket. Geez, the stereotypes people spread!

Sure, I know it isn't. But it still depends on where in Texas. If you're in Austin, yeah, you're probably not going to see people toting guns in supermarkets all over. If you're in Dallas or Houston, it'll be more common, but still not that common. If you're somewhere like San Antonio or Corpus Christi, it'll be even more common.

But yeah, there are vanishingly few places in the US where you should expect to be in the presence of gun-toting civilians while doing something as mundane as grocery shopping.

Post reply on HN