Earlier quoted context omitted.
The Signal protocol is very well designed but the implementation requires a telephone number (I know it is coming). That's a step removed from PGP which can be completely offline.
That's interesting and all, but my point is just that you'll have to stop and think about how many orders of magnitude separate the userbase sizes. A simpler way to make the same point would be that relative to modern cryptography, to a first approximation, nobody uses PGP.
Why I Wrote PGP (1999)
31–40 of 194 posts
Re: Why I Wrote PGP (1999)
#32There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…
Re: Why I Wrote PGP (1999)
#33> But while technology infrastructures can persist for generations, laws and policies can change overnight. Once a communications infrastructure optimized for surveillance becomes entrenched, a shift in political conditions may lead to abuse of this new-found power. Political conditions may shift with the election of a new government, or perhaps more abruptly from the bombing of a federal building. Prescient.
Re: Why I Wrote PGP (1999)
#34Earlier quoted context omitted.
That's interesting and all, but my point is just that you'll have to stop and think about how many orders of magnitude separate the userbase sizes. A simpler way to make the same point would be that relative to modern cryptography, to a first approximation, nobody uses PGP.
Maybe only the right people use PGP.
Re: Why I Wrote PGP (1999)
#35Earlier quoted context omitted.
I think one of the best arguments for using PGP is how long it's been around and is still in use, for two reasons: The encryption mechanisms have been tested many times by many people. And the tooling exists for just about platform and language.
This is pure snark and should be downvoted into oblivion, but by 2015 even Phil Zimmerman couldn't figure out the tooling: "Sorry, but I cannot decrypt this message. I don't have a version of PGP that runs on any of my devices" https://twitter.com/josephbonneau/status/638772283713060864
Re: Why I Wrote PGP (1999)
#36Earlier quoted context omitted.
I think one of the best arguments for using PGP is how long it's been around and is still in use, for two reasons: The encryption mechanisms have been tested many times by many people. And the tooling exists for just about platform and language.
The encryption mechanisms were tested, found wanting, and replaced in subsequent systems. PGP's installed base prevented them from keeping up. As a result, the constructions used in PGP today are essentially reviled by cryptography engineers.
Re: Why I Wrote PGP (1999)
#37Earlier quoted context omitted.
There isn't "an" alternative to PGP, because the idea of a single tool like PGP that covers all the use cases PGP attempts to cover has been revealed to be bankrupt. PGP does a bad job at practically everything it's applied to, because different problem domains ask different things from their cryptography. Backup tools want deduplication. Secure messaging wants relentless forward secrecy. Package signing systems want…
it's a little like someone invented a bad balanced binary tree It's a little like that culturally but it's almost entirely unlike that technically - a suboptimal data structure or algo tend to be just suboptimal-but-functional whereas bad cryptography and bad cryptography engineering often fail catastrophically. I know you know this, of course! But for one thing, someone used an iffy analogy on the internet, etc. For…
Re: Why I Wrote PGP (1999)
#38Earlier quoted context omitted.
The encryption mechanisms were tested, found wanting, and replaced in subsequent systems. PGP's installed base prevented them from keeping up. As a result, the constructions used in PGP today are essentially reviled by cryptography engineers.
What do you mean by "constructions"?
Re: Why I Wrote PGP (1999)
#39If I remember correctly, digital copies of the binaries and source code were prohibited for export as a munition, but publishing the source code in a book, made it a book, and thus eligible for export.
Re: Why I Wrote PGP (1999)
#40There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…