PGP is also a disaster in non-email scenarios. Many times I've had to implement systems that receive pgp encrypted files and then decrypt them and load them somewhere else. To this day there are no good libraries for this. There's either GPGMe, or shelling out to the gpg command line tool. Both options are terrible.
PGP Is Dead? (2018)
41–50 of 53 posts
Re: PGP Is Dead? (2018)
#42"Let's ditch open protocol X that has worked well for decades, in favour or closed protocol Y. Because of some transient issue with open protocol X, it's now time for open protocol X to die" Heard that before? It's as if if your doctor told you it's now time for you to die because you caught a cold.
https://signal.org/docs/ and https://en.wikipedia.org/wiki/Signal_Protocol#Implementation...
Re: PGP Is Dead? (2018)
#43Earlier quoted context omitted.
> Let's ditch open protocol X that has worked well for decades To be fair, I really can't put PGP in the category of "open protocol X that has worked well for decades"[1]. I'd welcome a closed protocol that actually works over an "open" one that's been functionally broken for years. [1] https://latacora.micro.blog/2019/07/16/the-pgp-problem.html
The problem is that email is store-and-forward, and there's no standard for MUAs to independently interact and perform key exchanges via PGP or anything, so end-to-end encrypted email will always be a much worse experience than end-to-end encrypted IM. Also, the heterogeneous MUA world, and the fact that users expect to be able to search their email even if encrypted, just makes end-to-end encrypted email a really to…
The Signal protocol, which is the one all the big service providers are licensing for the instant messaging encryption part of their service offering, is actually supposed to be designed for store and forward scenarios because messages can be sent when users are offline.
It is founded on Diffie-Hellman, a key exchange algorithm developed in the 1970s (the stuff in the article about PGP being developed "before we really knew anything about cryptography" seems bogus at best) that has very much managed to weather well.
I understood that elliptic curve Diffie-Hellman has been widely adopted primarily because it's just a compact way to represent the large numbers needed in order to make the key exchange process robust (I think the second coordinate of the curve can be represented with just a single bit, so more efficient than other approaches), but perhaps I am wrong or misguided on that.
Anyway, regardless - I don't trust the claims of perfect forward secrecy in services like WhatsApp and Signal for a moment - any more than I believe that Crypto AG sold devices that really worked. Perhaps the protocol implements PFS. But does WhatsApp really implement the protocol?
Besides, I recall reading that running the Unix command `strings` over the popular Signal messaging app revealed a static encryption key hardcoded into the application binary, which was used to encrypt all the attachments downloaded to the phone. Gaining access to the phone meant easily reading the messages (using Android accessibility features to "read them out loud") and with the hardcoded secret, easily decrypting the attachment storage too.
I've never read of a police force anywhere in the world actually shutting down citizen access to WhatsApp, at least not unless they're non-allies or otherwise considered hostile to the US. But I have heard of modified, PGP enabled BlackBerrys being seized by police forces all over the world because they really can't break them.
So my working method, fwiw: if I have something private to say that I do not wish to be snooped upon, I do send it over Signal or WhatsApp, but I say it with PGP, and then I delete it and ask the other party to do the same.
Re: PGP Is Dead? (2018)
#44Yes, PGP is dead but not because of any of the reasons this article points out. It's dead for a very simple reason: it's really hard to find active PGP/GPG keyservers. Fedora keyserver? Dead Debian keyserver? Dead openSUSE keyserver? Dead SKS keyserver pool? Dead keys.gnupg.net? Dead keys.openpgp.org? Half-dead (HKPS access not working, it seems only web is working) etc Very few keyservers are still online and some o…
Still going strong.
Re: PGP Is Dead? (2018)
#45> Of course, there are potential problems with allowing private companies to hold the keys to all of your sensitive conversations. But, these projects are generally less vulnerable than PGP because they are independent, says Green. > “When something goes wrong with WhatsApp, WhatsApp fixes it,” he says. “When something goes wrong in the amorphous PGP community, no one puts their hand up to fix it. This is some whacky…
The general argument is that open protocols tend to be stagnant while private ones are not, and that is true. Private protocols can iterate faster, have a vested financial interest to not lose customers, are often not required to be as backwards compatible which further slows updates and they can tightly integrate from backend to user. Open protocols always tend to be disjointed, i.e Email + PGP whereas something lik…
The speed of iteration is of little comfort when what they are iterating is against the wishes of the users who are captive to their network effects.[0]
> It's why 99.9% of users are on Twitter, and not on Mastodon.
I dare say that Twitter also generates 1000 times more revenue than all Mastodon instances combined, so all that's proven here is that having more money lets you make a more addictive website. That's not necessarily something we should be celebrating, especially as users are paying with their privacy and the stability of their societies.
Re: PGP Is Dead? (2018)
#46"Let's ditch open protocol X that has worked well for decades, in favour or closed protocol Y. Because of some transient issue with open protocol X, it's now time for open protocol X to die" Heard that before? It's as if if your doctor told you it's now time for you to die because you caught a cold.
> Let's ditch open protocol X that has worked well for decades To be fair, I really can't put PGP in the category of "open protocol X that has worked well for decades"[1]. I'd welcome a closed protocol that actually works over an "open" one that's been functionally broken for years. [1] https://latacora.micro.blog/2019/07/16/the-pgp-problem.html
Re: PGP Is Dead? (2018)
#47Be interested in various easy alternatives for encrypted messaging that non tech people will use. I've never had much luck with getting other people to use PGP, so many clients I have dealt with in the past have been all too quick to send sensitive information in plain text emails. The problem is, this info is often not super critical but not something you'd share with people, and generally the attitude is "No ones g…
For an email-based protocol, I would suggest Delta Chat[1], which is backwards compatible with existing email accounts, and follows the Autocrypt approach to PGP[2].
Re: PGP Is Dead? (2018)
#48Earlier quoted context omitted.
That's a bad thing. PGP has some really awful usability problems which have never been addressed. The paper "Why Johnny Can't Encrypt" described some of these issues in 1999, and a series of followups ("Why Johnny Still Can't Encrypt", "Why Johnny Still, Still Can't Encrypt"...) have come out over the years confirming that it still hasn't improved.
Someone should carry out a study where they test whether people can create a ProtonMail account and send an email from it (with a control group trying to do the same using Gmail). They could title the resulting research paper "Why Johnny Can Now Encrypt".
Re: PGP Is Dead? (2018)
#49Earlier quoted context omitted.
> you have to use it in your existing email client, and then you have to download keys, and then there’s this whole third issue of making sure they’re the right keys. If you use Thunderbird as your email client, then it will download the right keys for you automatically.[0] Actually it's two clicks to use the WKD support to download the key (assuming your correspondent's email provider supports that, as ProtonMail do…
Wait, wait, wait. ProtonMail only supports WKD lookups for desktop. I've had an open request for years to their support team to implement WKD lookups on mobile. As ProtonMail is the only PGP email provider with any mass traction, at this point it's just a middle finger to people who prefer to control their own selfhosted mailservers. I can't expect any PM user is going to be able to send me PGP encrypted mail when ma…
[0] https://github.com/ProtonMail/proton-contacts/pull/338
[1] https://github.com/ProtonMail/proton-mail-android/issues/44
Re: PGP Is Dead? (2018)
#50Earlier quoted context omitted.
The problem is that email is store-and-forward, and there's no standard for MUAs to independently interact and perform key exchanges via PGP or anything, so end-to-end encrypted email will always be a much worse experience than end-to-end encrypted IM. Also, the heterogeneous MUA world, and the fact that users expect to be able to search their email even if encrypted, just makes end-to-end encrypted email a really to…
https://signal.org/docs/specifications/x3dh/ The Signal protocol, which is the one all the big service providers are licensing for the instant messaging encryption part of their service offering, is actually supposed to be designed for store and forward scenarios because messages can be sent when users are offline. It is founded on Diffie-Hellman, a key exchange algorithm developed in the 1970s (the stuff in the arti…
We used to say that key management was the weakest link, but now I think the implementation itself is the weakest link.
Alice and Bob simply cannot defeat Mallory when Mallory is responsible for the implementation of the crypto that Alice and Bob are using to defeat Mallory.
But most users can't implement their own crypto. And the few users that could would stick out like sore thumbs. And they would still have key management headaches.
Basically, crypto can work to protect against criminals, but not against the state. That was always true anyways: the state can apply legal and nominally-illegal rubber hose cryptanalysis (i.e., they can beat you with a rubber hose, real or metaphorical, to get you to give up your secrets).