Live data from Hacker News

PGP Marks 30th Anniversary

philzimmermann.com

71–80 of 82 posts

Re: PGP Marks 30th Anniversary

#71

Earlier quoted context omitted.

> Sure, but malleability that has a close to zero chance of being a problem. https://efail.de https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt... This isn't even a controversy among cryptographers or cryptography engineers.

Efail is an excellent example of how the static encryption of OpenPGP used for encrypted email makes malleability irrelevant. To make the Efail attack against OpenPGP work requires the knowledge of the first 11 bytes/characters of the unencrypted message. The attacker would only get one guess. The recipient by necessity would see the attack message and would immediately know there was something going on. As a result…

the knowledge of the first 11 bytes/characters of the unencrypted message.

You probably know how that worked out for the Enigma.

Re: PGP Marks 30th Anniversary

#72

Earlier quoted context omitted.

> Sure, but malleability that has a close to zero chance of being a problem. https://efail.de https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt... This isn't even a controversy among cryptographers or cryptography engineers.

Efail is an excellent example of how the static encryption of OpenPGP used for encrypted email makes malleability irrelevant. To make the Efail attack against OpenPGP work requires the knowledge of the first 11 bytes/characters of the unencrypted message. The attacker would only get one guess. The recipient by necessity would see the attack message and would immediately know there was something going on. As a result…

> The attacker would only get one guess

As described in Efail, they don’t need to guess; they know the first 11 bytes with very, very high probability.

I doubt me being able to read a third of your encrypted emails is remotely acceptable to you.

> The recipient […] would see the attack message and would immediately know there was something going on.

That solace is fleeting when it is already too late. The attacker has your decrypted message.

Re: PGP Marks 30th Anniversary

#73

Earlier quoted context omitted.

> Sure, but malleability that has a close to zero chance of being a problem. https://efail.de https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt... This isn't even a controversy among cryptographers or cryptography engineers.

Efail is an excellent example of how the static encryption of OpenPGP used for encrypted email makes malleability irrelevant. To make the Efail attack against OpenPGP work requires the knowledge of the first 11 bytes/characters of the unencrypted message. The attacker would only get one guess. The recipient by necessity would see the attack message and would immediately know there was something going on. As a result…

You can just read the Efail paper and see how faulty this argument is. Because PGP treats authenticated ciphers as a "cargo cult", the Efail team could plausibly have broken almost 40% of Facebook's PGP-encrypted password reset mails. Further: they were able to abuse MIME encoding to get multiple guesses per email.

At any rate, none of this is something that anyone would accept from any modern cryptosystem, and the fact that PGP has you so backfooted that you'd feel the need to defend PGP's behavior here is a telling indication. "PGP: it's fine, as long as you don't use it to encrypt password reset emails. But for other emails it's fine, as long as the first 11 bytes of the email aren't guessable." Ok. Good note!

Maybe we should just put 128-bit nonces at the tops of all our emails. That just seems like common sense good engineering practice.

Re: PGP Marks 30th Anniversary

#74
post #67

Earlier quoted context omitted.

Forward secrecy is not of any real value in most instances of instant messaging as people usually keep their old messages around thus negating it. Using OpenPGP in the way that TLS is used would negate the advantage of static encryption and would cause the result to be as insecure as TLS. Probably worse as OpenPGP has not required all the band aids that TLS has ended up with.

Encryption is not of any real value if the threat you're describing is 'someone simply has access to all your plaintext messages'. This isn't a meaningful argument against forward secrecy.

The argument is that an attacker that gets your secret key material also gets your saved messages. If you had a more secure way to protect the saved messages then you could of used it to protect the secret key material. It is more or less the same problem.

Re: PGP Marks 30th Anniversary

#75
post #45

Please let PGP retire as a pioneer now and not as a laggard tomorrow. - https://latacora.micro.blog/2019/07/16/the-pgp-problem.html - https://soatok.blog/2020/07/08/gnu-a-heuristic-for-bad-crypt... - https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d695...

If we're sharing obligatory links, then a detailed critique of "The PGP Problem" is: https://articles.59.ca/doku.php?id=pgpfan:tpp It's true, though, that much work is needed to bring PGP up to the levels expected of modern crypto tools. Hopefully some of that will happen as a result of the work happening in the IETF: https://www.ietf.org/archive/id/draft-ietf-openpgp-crypto-re... and due to technology built around i…

> https://articles.59.ca/doku.php?id=pgpfan:tpp

Some rebuttals to that critique outline that the author doesn't fully understand the arguments Thomas Ptacek laid out, and may have a simplified understanding of PGP:

https://lobste.rs/s/tyaze3 and https://redd.it/negkdl

Re: PGP Marks 30th Anniversary

#76
post #69
post #22

Earlier quoted context omitted.

I've never seen a realistic threat model where Signal-style forward secrecy actually helps. Suppose a repressive regime captured one dissident can see a bunch of messages between them and other people, but theoretically some crypto nerd might have been able to forge those messages if the dissident has been carefully publishing the material they're supposed to publish and the cryptographer decided to run the forgery t…

I'm pretty you're thinking of deniability (from OTR) rather than forward secrecy. The forward secrecy in protocols like Signal allows for things like disappearing messages, which are then actually technically credible (the sender's and recipient's devices literally don't contain any information which would help to reconstruct the contents of their old messages). I think the former isn't really helpful in your scenari…

You're absolutely right. Still, I'd ask the same question about forward secrecy: is there a realistic model where they actually help? My impression is that people would generally keep their chat logs for as long as they're relevant, and so a message can only ever become unrecoverable by an attacker once it's irrelevant, in which case it's likely to also be irrelevant to an attacker. I guess maybe there are cases where someone is picked up and it's found they were also involved in some otherwise successful action years before?

Re: PGP Marks 30th Anniversary

#77

This brings back memories. I was an international student from Greece at the University of San Francisco, that fall, and I was present at a CS presentation that took place at the time (I'm not sure if it was Phill or not, but definitely one of the original authors). At the end of the presentation there was a pile of floppies that you could get a copy of the software. I got one along with my other classmates. Unfortun…

> I'm not sure if it was Phill or not One "l" (it's the "z" at the end of "Zimmermann" that's doubled).

My name ends in 'man', but Germans _always_ write it with two n's. I should never have taken a job for a German company...

Re: PGP Marks 30th Anniversary

#78
post #61
post #60

Earlier quoted context omitted.

This makes no sense to me. If I run a file through age, and then run that through a Reed-Solomon encoder, I now have a file that can be decoded even with single bit errors. But I think I also still have authenticated encryption. The cost is that my file takes a bit of extra space. Am I missing something?

You are not. Of course, the problem is that PGP doesn't get its informal resilience to single-bit errors through error-correcting codes on the ciphertext.

To be clear, OpenPGP does not correct errors. You still end up with corrupted data. It is just that you get back all your good data, no matter where it is in the file.

Re: PGP Marks 30th Anniversary

#79
post #73

Earlier quoted context omitted.

Efail is an excellent example of how the static encryption of OpenPGP used for encrypted email makes malleability irrelevant. To make the Efail attack against OpenPGP work requires the knowledge of the first 11 bytes/characters of the unencrypted message. The attacker would only get one guess. The recipient by necessity would see the attack message and would immediately know there was something going on. As a result…

You can just read the Efail paper and see how faulty this argument is. Because PGP treats authenticated ciphers as a "cargo cult", the Efail team could plausibly have broken almost 40% of Facebook's PGP-encrypted password reset mails. Further: they were able to abuse MIME encoding to get multiple guesses per email. At any rate, none of this is something that anyone would accept from any modern cryptosystem, and the f…

>Further: they were able to abuse MIME encoding to get multiple guesses per email.

The paper did not provide any example of an email client where this would work. I have as of yet not been able to reproduce this. Since there would be no practical reason for such behaviour the assertion requires some sort of proof.

Re: PGP Marks 30th Anniversary

#80
post #71

Earlier quoted context omitted.

Efail is an excellent example of how the static encryption of OpenPGP used for encrypted email makes malleability irrelevant. To make the Efail attack against OpenPGP work requires the knowledge of the first 11 bytes/characters of the unencrypted message. The attacker would only get one guess. The recipient by necessity would see the attack message and would immediately know there was something going on. As a result…

the knowledge of the first 11 bytes/characters of the unencrypted message. You probably know how that worked out for the Enigma.

I am not suggesting that email clients should entirely depend on OpenPGP email inherent resistance to oracle attacks, only pointing out that it exists. Presumably the Enigma operators were not putting their decrypted messages in envelopes before sending them off to their enemies. Efail was primarily a straight up plain text leak.

Plain text attacks come in distinct categories. The block ciphers used in OpenPGP are generally considered to be immune to the sort of plain text attacks used against Enigma.

Post reply on HN