Live data from Hacker News

PGP Is Dead? (2018)

wired.co.uk

31–40 of 53 posts

Re: PGP Is Dead? (2018)

#31

> Of course, there are potential problems with allowing private companies to hold the keys to all of your sensitive conversations. But, these projects are generally less vulnerable than PGP because they are independent, says Green. > “When something goes wrong with WhatsApp, WhatsApp fixes it,” he says. “When something goes wrong in the amorphous PGP community, no one puts their hand up to fix it. This is some whacky…

I've read through, it seems they are claiming it's for PGP to die because of someone else's bugs such as Outlook etc. And as per claiming the bug needs to be triggered by crafted html. So here come two more questions: 1. How does such html get injected into the email in the first place? 2. Why would someone ever use html instead of plain text for important emails that needs to be encrypted?

Re: PGP Is Dead? (2018)

#32

> Of course, there are potential problems with allowing private companies to hold the keys to all of your sensitive conversations. But, these projects are generally less vulnerable than PGP because they are independent, says Green. > “When something goes wrong with WhatsApp, WhatsApp fixes it,” he says. “When something goes wrong in the amorphous PGP community, no one puts their hand up to fix it. This is some whacky…

The general argument is that open protocols tend to be stagnant while private ones are not, and that is true. Private protocols can iterate faster, have a vested financial interest to not lose customers, are often not required to be as backwards compatible which further slows updates and they can tightly integrate from backend to user. Open protocols always tend to be disjointed, i.e Email + PGP whereas something lik…

It sounds like it is amazing we are all still using the IP stack to communicate.

Re: PGP Is Dead? (2018)

#34
post #6

> But the biggest problem with PGP is how difficult it is for people to use simply. "It’s a real pain," says Green. "There’s key management – you have to use it in your existing email client, and then you have to download keys, and then there’s this whole third issue of making sure they’re the right keys." How is this PGP's fault? The computing world has had 24 years to catch up with the standard, and frankly it does…

> you have to use it in your existing email client, and then you have to download keys, and then there’s this whole third issue of making sure they’re the right keys. If you use Thunderbird as your email client, then it will download the right keys for you automatically.[0] Actually it's two clicks to use the WKD support to download the key (assuming your correspondent's email provider supports that, as ProtonMail do…

Wait, wait, wait. ProtonMail only supports WKD lookups for desktop. I've had an open request for years to their support team to implement WKD lookups on mobile. As ProtonMail is the only PGP email provider with any mass traction, at this point it's just a middle finger to people who prefer to control their own selfhosted mailservers.

I can't expect any PM user is going to be able to send me PGP encrypted mail when many emails start from a mobile device.

Re: PGP Is Dead? (2018)

#35

Earlier quoted context omitted.

That's a bad thing. PGP has some really awful usability problems which have never been addressed. The paper "Why Johnny Can't Encrypt" described some of these issues in 1999, and a series of followups ("Why Johnny Still Can't Encrypt", "Why Johnny Still, Still Can't Encrypt"...) have come out over the years confirming that it still hasn't improved.

Someone should carry out a study where they test whether people can create a ProtonMail account and send an email from it (with a control group trying to do the same using Gmail). They could title the resulting research paper "Why Johnny Can Now Encrypt".

I've heard fairly compelling arguments for why ProtonMail isn't a good choice if you want privacy due to where your keys are saved.

Re: PGP Is Dead? (2018)

#37

Yes, PGP is dead but not because of any of the reasons this article points out. It's dead for a very simple reason: it's really hard to find active PGP/GPG keyservers. Fedora keyserver? Dead Debian keyserver? Dead openSUSE keyserver? Dead SKS keyserver pool? Dead keys.gnupg.net? Dead keys.openpgp.org? Half-dead (HKPS access not working, it seems only web is working) etc Very few keyservers are still online and some o…

> keys.openpgp.org? Half-dead (HKPS access not working, it seems only web is working) etc

Can you be more specific? HKPS looks fine from here, and we've had no downtimes on our monitoring.

Re: PGP Is Dead? (2018)

#38

Earlier quoted context omitted.

Someone should carry out a study where they test whether people can create a ProtonMail account and send an email from it (with a control group trying to do the same using Gmail). They could title the resulting research paper "Why Johnny Can Now Encrypt".

I've heard fairly compelling arguments for why ProtonMail isn't a good choice if you want privacy due to where your keys are saved.

And it still involves some significant trade-offs in terms of functionality: Potentially worse (spam) filtering and no full-text search unless you keep a full local copy of your mails around (which is rather unreasonable on a phone and impossible with webmail).

And those trade-offs are more or less fundamental if you want to access your mail from multiple devices, but at the same time don't want to trust your server to handle decrypted mails.

Re: PGP Is Dead? (2018)

#39

Earlier quoted context omitted.

I've heard fairly compelling arguments for why ProtonMail isn't a good choice if you want privacy due to where your keys are saved.

And it still involves some significant trade-offs in terms of functionality: Potentially worse (spam) filtering and no full-text search unless you keep a full local copy of your mails around (which is rather unreasonable on a phone and impossible with webmail). And those trade-offs are more or less fundamental if you want to access your mail from multiple devices, but at the same time don't want to trust your server…

All depends on your threat model. I would never expect to receive sensitive information via email in 2021 when there are protocols like Matrix available. Even my bank and utility providers only send me email notifications telling me to login to their platform to view sensitive information. At this point, other than select business communications, email has been relegated to a two-way notification system for most people.

Sure, I send a lot of emails, but likewise, if I had anything worth keeping private, I certainly wouldn't be sending it in an email, even an encrypted one.

Re: PGP Is Dead? (2018)

#40
post #37

Yes, PGP is dead but not because of any of the reasons this article points out. It's dead for a very simple reason: it's really hard to find active PGP/GPG keyservers. Fedora keyserver? Dead Debian keyserver? Dead openSUSE keyserver? Dead SKS keyserver pool? Dead keys.gnupg.net? Dead keys.openpgp.org? Half-dead (HKPS access not working, it seems only web is working) etc Very few keyservers are still online and some o…

> keys.openpgp.org? Half-dead (HKPS access not working, it seems only web is working) etc Can you be more specific? HKPS looks fine from here, and we've had no downtimes on our monitoring.

[zxspectrum@zxspectrum ~]$ gpg --refresh-keys

gpg: refreshing 204 keys from hkps://keys.openpgp.org

gpg: keyserver refresh failed: No keyserver available

Post reply on HN