PGP Is Dead? (2018)
wired.co.uk
PGP Is Dead? (2018)
1–10 of 53 posts
Re: PGP Is Dead? (2018)
#2Re: PGP Is Dead? (2018)
#3> “When something goes wrong with WhatsApp, WhatsApp fixes it,” he says. “When something goes wrong in the amorphous PGP community, no one puts their hand up to fix it.
This is some whacky reasoning, explaining away the questionable trust of for-profit entities holding your keys by saying "at least they're segregated islands of questionable moral fibre!"
My distrust of WhatsApp and the like is far less about fixable vulnerabilities, and far more about their underlying business models.
With raw tech like PGP, this isn't a concern - I don't have to trust a key server not to decrypt my data and sell it to advertisers _because they theoretically can't_
---
Overall this article seems to play pretty fast and loose with argument logic, seems a little weasel-wordy from my (very) brief skim. Are they saying PGP is dead because the UX sucks, or because there are vulnerabilities?
All feels very "seatbelts are uncomfortable, but modern cars are super safe - just trust that other drivers won't be idiots"
Re: PGP Is Dead? (2018)
#4Just because it's quicker and easier to pop it in the microwave, doesn't mean that it's healthier than a home cooked meal.
Re: PGP Is Dead? (2018)
#5May 2018 specifically
Re: PGP Is Dead? (2018)
#6How is this PGP's fault? The computing world has had 24 years to catch up with the standard, and frankly it does everything listed here out of the box on Linux. Microsoft, Apple and Google have all been dragging their feet in the sand when it comes to actually implementing it, so the onus really falls on them as far as I can tell.
PGP is still Pretty Good Privacy: not perfect by any means, but a considerable step up from plaintext. Maybe there are credible threats to it's security, but most people reading this will probably be dead before it's implemented.
Re: PGP Is Dead? (2018)
#7Just because it's quicker and easier to pop it in the microwave, doesn't mean that it's healthier than a home cooked meal.
Re: PGP Is Dead? (2018)
#8I think we need to talk about layering more. There's no shortage of compute cycles today. Each message should go through encapsulated rounds of encryption, preserving the older standards until it can be definitively proven they are broken, which has not been the case with RSA. At least one of those layers should be multivariate or lattice post quantum scheme. https://github.com/polysome/vane
Re: PGP Is Dead? (2018)
#9Re: PGP Is Dead? (2018)
#10> Of course, there are potential problems with allowing private companies to hold the keys to all of your sensitive conversations. But, these projects are generally less vulnerable than PGP because they are independent, says Green. > “When something goes wrong with WhatsApp, WhatsApp fixes it,” he says. “When something goes wrong in the amorphous PGP community, no one puts their hand up to fix it. This is some whacky…
Private protocols can iterate faster, have a vested financial interest to not lose customers, are often not required to be as backwards compatible which further slows updates and they can tightly integrate from backend to user. Open protocols always tend to be disjointed, i.e Email + PGP whereas something like Signal is just integrated because it's all under control of a single entity.
In reality, and this is evidenced by user choice, that level of integration is important. It's why 99.9% of users are on Twitter, and not on Mastodon.