Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

251–260 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#251
post #196

Earlier quoted context omitted.

It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…

> the intent of it was to protect citizens' right to arm themselves Unlike european countries, the american frontier was a dangerous place where every household needed a gun. Armed citizens existed regardless whether there was a militia or not.

While that may be true, that was not the intent of the 2nd amendment, which was there to ensure that regular citizens were both involved in the protection of the country's interests, and could act as a counter (by force, if necessary) to their own country if it decided to try to grab too much power and become tyrannical.

Enshrining this right in the constitution had little to do with frontier safety.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#253

Earlier quoted context omitted.

It's telling that the most common example of a widespread use of PGP (modern messaging applications exchange more messages in a day than OpenPGP has ever exchanged) is software update schemes, because software update cryptography is both a solved problem (just use signify) and doesn't have network effects; it's a "trust anchor" application. At least with PGP email, you can make the argument that PGP sticks around bec…

> software update cryptography is both a solved problem (just use signify) Well, just use TUF [1] and in-toto [2] ;) [1] https://theupdateframework.io/ [2] https://in-toto.io/

Note that TUF is great for things with multiple contributiors (think npm or pypa).

For the simple case of "a single publisher publishes update for a single product", TUF is an overkill. Something like signify or seccure will be way easier to set up and use.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#254
post #239

Earlier quoted context omitted.

Maybe so, but then we need to come up with more words. As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.)

> As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.) Which article or amendment of the U.S. Constitution forbids a state to leave without permission of the U.S.?

There is of course no clause of the constitution that forbids secession but SCOTUS currently interprets the constitution as creating an "indestructible union" if I recall the language correctly.

And good luck finding a good vehicle to overturn that precedent.

The TEU at least provides an explicit process for leaving

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#255
post #105
post #61

Earlier quoted context omitted.

> 2. Adoption hasn't been enough to be able to ban untrusted senders. This could still be quite useful for, say, a hard requirement that *@example.com must have signatures but it doesn't help with really common phishing tactics like pretending to be a vendor, business partner, etc. Preventing forgery of @example.com is nice, but sadly doesn't matter that much, because a message fro "Your Boss" is just going to show u…

Or even “hey, I’m away from the office and lost my company phone. Can you help me …” attempts using an obvious third-party service. All of these have fooled people in the past and you really need high adoption rates to seriously reduce the odds.

The one that almost got me was

      From: "John Q Boss"
      Subject: "the blog is down"

      Can you check http://blog.example.com
Of course, that came in on my phone, as I was leaving for the day, and phone doesn't show email address or link destination. :(

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#256
post #209

Earlier quoted context omitted.

Right, so why talk about the standard when you mean, specifically, GnuPG? If you want an explanation of why GnuPG is dangerous for anything besides email, let me know. But parent post was very specifically NOT about GnuPG- it was about OpenPGP.

because gnupg is not the only implementation.

Yes, that's what I said, and why I was asking!

What does the OpenPGP format bring to the table, BESIDES HAVING A COMMONLY AVAILABLE IMPLEMENTATION IN GNUPG?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#257
post #196

Earlier quoted context omitted.

It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…

I have a different perspective. I think that the scope of the 2nd amendment has narrowed over the years. In 1776, private citizens owned every kind and sort of weapon used by the military. Ordinary people owned cannons, were instructed to put cannons on their private ships to defend against pirates, and owned the same sorts of muskets used by the army. The modern equivalent would be buying tanks at Walmart for cash a…

> By the way, the archaic meaning of "regulated" means "properly disciplined and drilled". It did not refer to control or supervision by a state.

That still leaves open the question of what levels of discipline and drilling the (federal or state) government could demand of someone for them to be included in the Militia.

It is already accepted that felons and the mentally ill may be prevented from exercising 2nd Amendment rights, so it is perhaps not inconceivable that there could be minimum and maximum age limits, or minimum numbers of training / inspection days for people to be deemed validly part of the Militia.

Whether any such changes would reduce gun crimes, or increase crimes generally, or be politically viable or desirable, are separate questions.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#258

Earlier quoted context omitted.

Side note: don’t call the countries in the European Union “states”. They’re sovereign countries that have committed themselves through treaties to the Union, not a US like government body

When we nitpick, "country" = geographic unit, "state" = political unit. The United States is itself a state, albeit a federation of smaller states.

This is a nice distinction, actually. It means we can think about "stateless countries" (like Western Sahara, perhaps), and "countryless states" (like the Sovereign Military Order of Malta).

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#259

> For reasons associated with U.S. export restrictions, no cryptographic security of any kind is likely to be included in the original sources https://bugzilla.mozilla.org/show_bug.cgi?id=22687#c1 Creepiest thing with seeing this ticket (again?) is noticing that the first comment is about that is used to be illegal to write anything with cryptographic security in the US and sell/give it to the outside world. https://…

That's why there were those "illegal" t-shirts with the RSA algorithm printed out in Perl. But I have a more pragmatic approach. If nuclear launch codes were written out on t-shirts I wouldn't be happy about it either. I think the real problem is ignorance. The US's main role after 1945, and the role of the UN, was and is to prevent another world war. Whether by virtue or by ignorance they have been successful, with…

> If nuclear launch codes were written out on t-shirts I wouldn't be happy about it either.

If the government only found out that its nuclear launch codes were leaked because it saw them written on someone's t-shirt, I would be unhappy about the government, not the t-shirt.

Also, if the government decided to ban the t-shirts rather than changing the codes, I would be even more unhappy.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#260
post #89

Earlier quoted context omitted.

Signal pumps all traffic across AWS infrastructure, where the simplest of all traffic analysis can deanonymize its users. Signal relies on phone numbers (for reasons), which again is not exactly the best "metadata" to carry around. If you look at the NSA material in the Snowden cache, it becomes clear that the whole "US kills based on metadata" is fed by piggybacking exactly on such systems, like deanonymization of s…

One can imagine all sorts of thing. Are you saying that you routinely send PGP email with Subject headers encrypted, using temporary mail addresses and pseudonyms? This is your routine email use, with a bunch of correspondents who do the same? Or, along with "random relay ordering on SMTP level", it's just something you're imagining? If you're saying the PGP use you imagine would be more secure than the Signal use th…

> If you're saying the PGP use you imagine would be more secure than the Signal use that actually exists...

To present an iron-man argument instead of a straw-man, imagine they were comparing Delta Chat to Signal, and pointing out that Delta Chat does encrypt subject headers[0], and that Signal users typically don't use temporary phone numbers (which are harder to obtain than temporary email addresses).

If you want, you could try comparing Signal's proprietary network versus the global SMTP network in terms of how secure they are against traffic timing analysis.

[0] https://delta.chat/en/help#how-does-delta-chat-protect-my-me...

Post reply on HN