Live data from Hacker News

The PGP problem (2019)

latacora.com

21–30 of 121 posts

Re: The PGP problem (2019)

#21
After reading the PyCon 2016 presentation about wormhole, and say my understanding of channels is correct (that is, each session on the same wireless network constitutes a session). What's stopping a hostile 3rd party, who wishes to stop a file transfer from happening, from spamming every channel with random codes?

Re: The PGP problem (2019)

#22
post #11

Earlier quoted context omitted.

I’m still frustrated by the criticism because I internalized it a couple of years ago and tried to move to age+minisig because those are the only 2 scenarios I personally care about. The overall experience was annoying given that the problems with pgp/gpg are esoteric and abstract that unless I’m personally are worried about a targeted attack against me, they are fine-ish. If someone scotch tapes age+minisig and conv…

Has Tarsnap become inadequate, security-wise? The service may be expensive for a standard backup. It had a serious bug in 2011, but hasn't it been adequate since then?

I don’t know anything that makes me think it’s inadequate per se, but it’s also been more than 10 years since I thought about it. Restic, gocryptfs, and/or age are far more flexible, generic and flat out better in managing encrypted files/backups depending on how you want to orchestrate it. Restic can do everything, gocryptfs+rclone can do more, etc.

Re: The PGP problem (2019)

#23
post #16
post #9

How does this help people who are not following this issue regularly? gpg protected Snowden, and this article promotes tools by one of the cryptographers who promoted non-hybrid encryption: https://blog.cr.yp.to/20251004-weakened.html#agreement So what to do? PGP by the way never claimed to prevent traffic analysis, mixmaster was the layer that somehow got dropped, unlike Tor.

You could also say Cryptocat protected Snowden; he used it to communicate with reporters. So, that's how well that argument holds up.

https://en.wikipedia.org/wiki/Cryptocat#Reception_and_usage

"In June 2013, Cryptocat was used by journalist Glenn Greenwald while in Hong Kong to meet NSA whistleblower Edward Snowden for the first time, after other encryption software failed to work."

So it was used when Snowden was already on the run, other software failed and the communication did not have to be confidential for the long term.

It would also be an indictment of messaging services as opposed to gpg. gpg has the advantage that there is no money in it, so there are unlikely to be industry or deep state shills.

Re: The PGP problem (2019)

#25

Even though I read so many posts criticizing PGP, it's still difficult for me to find an alternative. He states in the article that being a "Swiss Army Knife" is bad. I understand the argument, but this is precisely what makes GPG so powerful. The scheme of public keys, private keys, revoke, embedded WOT, files, texts, everything. They urgently need to make a "modern version" of GPG. He needs a replacement, otherwise…

The so-called web of trust is meaningless security theatre.

>They urgently need to make a "modern version" of GPG.

Absolutely not.

Re: The PGP problem (2019)

#27
post #7
post #2

Probably resurfacing, because we have some new attacks thanks to CCC. [0] [0] https://news.ycombinator.com/item?id=46453461

Worth noting: minisign and age were also affected by a couple things here. GnuPG has decided a couple things are out of scope, fixed a couple others. Not all is in distro packages yet. age didn't have the clearest way to report things - discord is apparently the point of contact. Which will probably improve soon. minisign was affected by most everything GnuPG was, but had a faster turnaround to patching.

The mark of good security is not "has no bugs". It's how the maintainers respond to security-relevant bugs.

Re: The PGP problem (2019)

#28
post #16

Earlier quoted context omitted.

You could also say Cryptocat protected Snowden; he used it to communicate with reporters. So, that's how well that argument holds up.

https://en.wikipedia.org/wiki/Cryptocat#Reception_and_usage "In June 2013, Cryptocat was used by journalist Glenn Greenwald while in Hong Kong to meet NSA whistleblower Edward Snowden for the first time, after other encryption software failed to work." So it was used when Snowden was already on the run, other software failed and the communication did not have to be confidential for the long term. It would also be an…

Huh? There's no money in anything we're talking about here.

Re: The PGP problem (2019)

#29
post #28

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cryptocat#Reception_and_usage "In June 2013, Cryptocat was used by journalist Glenn Greenwald while in Hong Kong to meet NSA whistleblower Edward Snowden for the first time, after other encryption software failed to work." So it was used when Snowden was already on the run, other software failed and the communication did not have to be confidential for the long term. It would also be an…

Huh? There's no money in anything we're talking about here.

[flagged]

Re: The PGP problem (2019)

#30
post #7

Earlier quoted context omitted.

Worth noting: minisign and age were also affected by a couple things here. GnuPG has decided a couple things are out of scope, fixed a couple others. Not all is in distro packages yet. age didn't have the clearest way to report things - discord is apparently the point of contact. Which will probably improve soon. minisign was affected by most everything GnuPG was, but had a faster turnaround to patching.

The mark of good security is not "has no bugs". It's how the maintainers respond to security-relevant bugs.

… in which case, ‘on Discord’ is not off to a good start.
Post reply on HN