Live data from Hacker News

Bruce Schneier has changed his PGP key to 4096 bits

news.ycombinator.com

11–20 of 144 posts

Re: Bruce Schneier has changed his PGP key to 4096 bits

#11
post #9

Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.

Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)

As it's commonly called: "endpoint security".

If his computers have ever been compromised, his PGP private key would likely be as well. Considering all the news about US gov spending millions on rootkits, it was likely a wise choice to generate a new one in case a previous one was likely to have been compromised.

I'd guess Schiener would be a target of interest by some state (as is anyone working with encryption it seems).

Re: Bruce Schneier has changed his PGP key to 4096 bits

#12
post #9

Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.

If we loosen "lost" in "he lost his private key" to include "lost control of", then that still works.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#14
post #7

Earlier quoted context omitted.

You might be able to find a nearby willing Debian developer https://wiki.debian.org/Keysigning/Offers#US If you're near a university or work somewhere in tech you'll probably be able to find a DD within a degree or two in your network.

Looks like there is exactly one in my state. I will reach out to him. Thanks.

Hi NJ :D could be CT but figured it'd be New England at that point. Good luck though, but either way there are a lot in NY so maybe some luck there.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#15
post #9

Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.

Or, similarly:

- Snowden et al asked him to create a new keypair with very strict cleanroom practices[0] to be sure as to the sanctity of the private key. It's trivial to bump up the key length when doing so.

[0]: See the August 18 NYT article on Laura Poitras and Glenn Greenwald for a peek at the "operational security" that Snowden demanded. http://www.nytimes.com/2013/08/18/magazine/laura-poitras-sno...

Re: Bruce Schneier has changed his PGP key to 4096 bits

#16
post #9

Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.

Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)

Alternatively, it could mean that while he uses it often, he does not often use it for things that are actually important. Faced with unusually important communication, he may have decided to create a new key that he could be confident was still private.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#18
post #9

Or: - he really doesn't use his PGP key all that often, had the same one for 16 years on god knows how many computers, and decided that if he's going to generate a new one, he might as well send a message with it.

Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both? (and to be clear, my intent is not to bait, i'm actually curious)

Most people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.

Re: Bruce Schneier has changed his PGP key to 4096 bits

#20

So I have a GPG key. I used it a couple of times. Currently, it's most useful to me to sign my own Debian package repository. However, I can't seem to figure out how to get into the whole Web of Trust thing. Nobody I know has their own GPG/PGP key that they use and have signed by others and tools like BigLumber and other places where I looked for key signing parties have not turned up any results. I not spending all…

Check out http://www.biglumber.com/ as well
Post reply on HN