Live data from Hacker News

Making PGP Key Management Invisible So Johnny Can Encrypt

blog.whiteout.io

41–50 of 78 posts

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#41
post #25

Earlier quoted context omitted.

Someone made a fake key for each of the participants in a particular keysigning party in October 2013 (including me) and uploaded the fake keys to keyservers. Because the creation date of the fake key for me is newer than the creation date of my real key, apparently Enigmail is suggesting it to people and they're choosing to use it, despite the lack of signatures. More than a dozen different people have now sent me e…

This sounds like an implementation as opposed to design flaw. Enigmail should be throwing up red flags all over the place when duplicates exist. That being said, this is perilously close to the "No True Scotsman" fallacy.

I'd be really, really cautious about throwing "No True Scotsman" at Seth David Schoen and Erinn Clark.

https://en.wikipedia.org/wiki/Seth_Schoen

His hopelessly out-of-date homepage: http://www.loyalty.org/~schoen/

That said, yes, PGP has a notable failing in that there's no reliable method for repudiating a key, particularly one generated by a hostile party.

If you've hung on to your key revocation certificate you can revoke a key you have generated. But that's only a small part of the battle.

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#42

Earlier quoted context omitted.

This sounds like an implementation as opposed to design flaw. Enigmail should be throwing up red flags all over the place when duplicates exist. That being said, this is perilously close to the "No True Scotsman" fallacy.

I'd be really, really cautious about throwing "No True Scotsman" at Seth David Schoen and Erinn Clark. https://en.wikipedia.org/wiki/Seth_Schoen His hopelessly out-of-date homepage: http://www.loyalty.org/~schoen/ That said, yes, PGP has a notable failing in that there's no reliable method for repudiating a key, particularly one generated by a hostile party. If you've hung on to your key revocation certificate you ca…

I'm sorry my homepage is out of date; thanks for the reminder. It seems like it's been a decade or so since I updated it.

I normally check signatures when downloading a new key, particularly as a way of distinguishing between multiple keys available on a keyserver. But I don't have a way to force other people who are writing to me to do that, and apparently at least the Enigmail users often don't.

Edit: Erinn is a more cautious PGP user than I am (with an extraordinarily important key!), but I expect she also has no way of forcing people to check that they have the right key when e-mailing her.

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#43
post #33

Earlier quoted context omitted.

Question. Do you plan on gossiping with or mirroring the SKS pools? I would love to be able to just search keybase for a public key rather than both: https://diafygi.github.io/publickeyjs/

Cool site! Max Krohn ( https://keybase.io/max ) and I are meeting with some people working on various PGP projects in Germany in April, and one of the things on our personal agenda is the ideal future of key distribution. We don't really want to be a sole place to look up these keybase-style social media proofs. We also don't think they belong inside the keys themselves. One complication: looking up a key by email an…

Makes sense. If possible, I'd like to request at least gossiping with servers in the SKS pool. Right now, when someone signs my key and sends it to the pool via gpg --send-key, it doesn't get updated in keybase :(

Second, for public keys that are signed by other fingerprints in keybase, it would be nice to have those listed in my trackers list.

Finally, for people who upload a public key to keybase, it would be great if that would gossip to the pool so I could get it via gpg --recv-key.

Thanks for the great work so far!

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#44
post #23
post #6

Two things that would make this have more hope of becoming a standard: 1) open source the key server with the REST-API 2) allow domain owners to define their own key server via a DNS TXT entry

1. What's wrong with the existing key server protocol? 2. Why TXT and not SRV?

1. From reading their post, it seems like they made their own REST API for the key server. So it would be nice if they open sourced the service behind it, to alleviate fears of lock in.

2. You're right, it probably should be SRV.

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#45
post #12

https://keybase.io/ with it's social media identity proofs have been interesting way to allow finding contacts in my social network's pgp keys. Edit: I also have invites available if you are interested in checking it out. Contact me via my HN profile

This is fascinating concept, especially since I've always felt that my PGP key was sitting out there mostly useless since no one I know personally signs their emails or even knows someone who signs emails. However, wouldn't the weak part here be if my twitter (or other public) account was compromised somehow? Or if someone just impersonated me and sent a "unique tweet" pretending to be me?

How does HN feel about that identity aspect? Is it supposed to replaced key signing or just augment it?

I'm frankly not sure I fully get my head around the concept, even after reading this page:

https://keybase.io/docs/tracking

But it's Friday afternoon, so that could be it...

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#46

Earlier quoted context omitted.

This sounds like an implementation as opposed to design flaw. Enigmail should be throwing up red flags all over the place when duplicates exist. That being said, this is perilously close to the "No True Scotsman" fallacy.

I'd be really, really cautious about throwing "No True Scotsman" at Seth David Schoen and Erinn Clark. https://en.wikipedia.org/wiki/Seth_Schoen His hopelessly out-of-date homepage: http://www.loyalty.org/~schoen/ That said, yes, PGP has a notable failing in that there's no reliable method for repudiating a key, particularly one generated by a hostile party. If you've hung on to your key revocation certificate you ca…

No, I mean that my argument there was perilously close to said fallacy.

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#47
post #42

Earlier quoted context omitted.

I'd be really, really cautious about throwing "No True Scotsman" at Seth David Schoen and Erinn Clark. https://en.wikipedia.org/wiki/Seth_Schoen His hopelessly out-of-date homepage: http://www.loyalty.org/~schoen/ That said, yes, PGP has a notable failing in that there's no reliable method for repudiating a key, particularly one generated by a hostile party. If you've hung on to your key revocation certificate you ca…

I'm sorry my homepage is out of date; thanks for the reminder. It seems like it's been a decade or so since I updated it. I normally check signatures when downloading a new key, particularly as a way of distinguishing between multiple keys available on a keyserver. But I don't have a way to force other people who are writing to me to do that, and apparently at least the Enigmail users often don't. Edit: Erinn is a mo…

I check up on you from time to time. Virtunova's been offline for ages as well.

I'm kicking around ways of making email more reliable, one option that occurs to me is key negotiation at transmit time, or as part of the delivery process. That is: a user's home mailserver would be key-aware. Though that too is subject to skulduggery.

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - -----BEGIN PGP MESSAGE-----
    Version: GnuPG v1
    
    hQIMA7xDFKsys5UtARAAxMhajUMAOzPLYSruMqKC8tOX1Ky0TScotJICEcfl2MML
    gUvhTShRK0UPLtuXxT+emnKaqAJfPM4RzcuMo6mSIzEnZKGjCa49E+mQIp2129hH
    dktyMfNeA7bF2n+FxFpSmv9hF4IihVXwOmdu3OzXrEjYcHpYR8kh5MoANErJAMPj
    mCWPfpqqxpLQ7IQGUCu3FYZ1/pbHEfmKa/nOpvAr4zGciFb9p8Jir2ujbxfRGySU
    RVEplGeC4vLUlwnRjXENCONtJVKv4oL+e+Z+MKziKhoiNGX5NQTA4AEc958a7Aew
    HVQDoRnqYZf9pa4hiqIR2TNyxKfkAxrUtTs8g19VDKPynmTR5oiao+fpZShzMVLF
    Wza0KDi+fOqCbZT/1iBVkkyiQt1hEvQBSVyqoxK7MPNshn5dRpFY+Y8oSFHcFosM
    +TYk0O9LWMfPjW9eFOpBQHi0orUgJ+X45Pxukn2aBC3Sw9r57ubXTeTTJ9d4Xk9W
    QU6SZdL+MrUIFIjOPcd9fB3DCGeT4P56Y+c2L2nkOQRbbwJKRwynBNuJ1YuoMcIS
    +3x1+UQzjrCv1E1K0MkGayI4SCFLznDK3zZOzVVpGesUXeI7tm8ix6q+GO2FfhbC
    ClBirm6OJcSKr0E0ABVR8tsAyJn2fECA9ssuIm7x+sC8RcjRrzMGgx/eVTXASdSF
    AgwDo9/BBkoA4X8BEACAlqrZ3xGRdbJILBXjbmiOe264sNQuQ+DD4OFLhgMI88Cu
    WmpKOlHjLDcgmgWLUcbjKCYEgNpqysSUexPNv2sk7sjqBhyPK3UcqgZnnrONbuea
    IcJZ3NBTBSkmzv3c9bGFCV7Mt1uKp3gajUXCrlZ1otWo9xRLwlDd1VolrgoWqwot
    P0qHclUuVa/DFuHsplosY43zOfcVm9z1thMJE/avgSqwSej50JHvawADVAiVCm8U
    pmKE73BDV5uo20xjaZ4rhUcc4iv+VKnENNPR1mYPjPo92bdtRF7zmwCwum3nj37c
    53/Q6AvUXt0gCwOIfAaARwyZZGT1d9BC4NCc8cB70lvHQHTkT/qLbZbYoi2TA7bd
    k+cR683BuGrBfTLlSXAwvKzppsWocpiJdTdzYlatPH5sAxb4q1MDLpr++hr5V+cd
    yHj+8W0SEjsxqNUN3seHpkM/kefLN/gq0vBzb6kJUVz4eJM7nPlmMo5hmwT0P+HW
    s+Pn/ZqLUrLlQyuWIEsoONq95DZ1FjMSgQB37+4Oo0wtmGG3fNF6hR5rgp5mkEu/
    7zuTzRA51s5kz/pVoqC3FA70S5ZdiIRUoUggjb4W+Rwan2crOzfzVH6JZMRAqlPe
    4Y2fQRGU5SDmByR07DsgSXsLgwPyTy/TFtT37B70zw6CH0p/XYTGbsG7ta3G+dJb
    AQFoYZyRld4hhNL5BtvrM9WCL9XTwnuYACN0dhW/ym6E7HLY3gq5ahMQj4vLlafY
    Z68YabNxRG0eF7errJDWg+itjtgge4zgaXxPUf/h/gpPE5+chSuaSfHpjw==
    =zY2a
    - -----END PGP MESSAGE-----
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1
    
    iQIcBAEBAgAGBQJU1UEGAAoJEKxvHoRCCre9JiIP/iZQoi2C501kj8bMHNMF05d4
    4LwEsfmOFBPfDlK5+YP4U48j9nJyMt1eQcA5UqsHGAsZ78hnmXsZTD+LwEE0Tn7f
    DD5gMWLt4vulKxblR1Md8A+lfAK0YYzH1dhJbg6KWF9znpg7zeb34t4fWz82bGZ8
    FmEJuiI4HqfxCfKwmd8knDZ0rrrBJcZAsc/v5KnVN8zB+bumUX9SLcR1fF1p62nK
    tfB/Ri3taEPoz9OXfC4Lmniovu0BbiqIdWBp9vBvYQHp0jIVReKJE+O+NuvGkApR
    +oZp17S6nkf3LZTLzSi1bO6TOetMnG+TZhCXHP45JcPTg8Hr7MftuymD+qjbRhLR
    WnV6MwYZZns1ZWBjXh5w1zx8vhKyxTbJ0rupoY82hg3nXPInTCyZZAAwFE9+Hsh4
    Dbxflr6+9Xt0Mp+BQvkEsL45haCGKtnpyzDrfYqkomKq03D09MIRQFkG8ZX9KEuU
    kviw7rQjvDKetwN1gmI+gdEwAmJeDH0gCUijjTOKmy8nBD4i2x4GknDxyUX24HYf
    FpyIRtV/MlJwjxa2+0J5vC92QhDzT3rCsAQC/iHkm+B+HdxOpM26Qyu6WbwhXrY5
    /E1kYTK6gTiaeDcaax2/V62OTie4JbXV0/ZUXfDMyVa0Yr1Qi0Y7aArB1A0xB6Pg
    5tpyUQ14Uo9fGMXoLKfa
    =py+D
    -----END PGP SIGNATURE-----

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#48
post #42

Earlier quoted context omitted.

I'd be really, really cautious about throwing "No True Scotsman" at Seth David Schoen and Erinn Clark. https://en.wikipedia.org/wiki/Seth_Schoen His hopelessly out-of-date homepage: http://www.loyalty.org/~schoen/ That said, yes, PGP has a notable failing in that there's no reliable method for repudiating a key, particularly one generated by a hostile party. If you've hung on to your key revocation certificate you ca…

I'm sorry my homepage is out of date; thanks for the reminder. It seems like it's been a decade or so since I updated it. I normally check signatures when downloading a new key, particularly as a way of distinguishing between multiple keys available on a keyserver. But I don't have a way to force other people who are writing to me to do that, and apparently at least the Enigmail users often don't. Edit: Erinn is a mo…

Including your key signature everywhere you post your email address (homepage, business card, email signature, etc.) is a good practice. It's not perfect, but it's better than teaching users to go straight to a keyserver.

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#49
post #12

https://keybase.io/ with it's social media identity proofs have been interesting way to allow finding contacts in my social network's pgp keys. Edit: I also have invites available if you are interested in checking it out. Contact me via my HN profile

This is fascinating concept, especially since I've always felt that my PGP key was sitting out there mostly useless since no one I know personally signs their emails or even knows someone who signs emails. However, wouldn't the weak part here be if my twitter (or other public) account was compromised somehow? Or if someone just impersonated me and sent a "unique tweet" pretending to be me? How does HN feel about that…

This is a good question: generally if all you know about someone is their twitter name, and that's it, then a compromise of their twitter account could lead to a compromise of their key announcement.

Even this case is mitigated because of the timestamping: a compromise would have to be a public compromise on an ongoing basis, and everyone in the world would have to see the same compromise, including the alleged twitter holder. Tracker statements add to the timestamping: when someone runs the Keybase client and tracks them, they sign a statement saying on date X twitter user Y had that public key and they checked it.

The second advantage is that a person is typically a sum of many identities. Consider a known developer who signs code using their Keybase announced key. (Let's say Jeremy Ashkenas does (does he?) - anyway, he's on Keybase as https://keybase.io/jashkenas). His public key is announced on his Github and Twitter accounts, both of which are known. He signs those statements with the matching private key. If you ask Keybase for his key, you get 3 things: Keybase telling you what it is, Twitter agreeing with you, Github agreeing with you, and bitcoin telling you everyone in the world has gotten the same answer for those 3 accounts for the last few months. And CLI tracker statements timestamping, too.

Re: Making PGP Key Management Invisible So Johnny Can Encrypt

#50
post #12

https://keybase.io/ with it's social media identity proofs have been interesting way to allow finding contacts in my social network's pgp keys. Edit: I also have invites available if you are interested in checking it out. Contact me via my HN profile

Two things we're particularly proud of at Keybase are (1) that there's no server trust of these proofs, and (2) we pin the entire state of the directory to the bitcoin blockchain, to prevent forking. [1] In other words, if you ask for Twitter user X's public key, your client can check that proof on twitter itself (rather than trusting that a key server did it for you, like it would with email proofs), and it can trus…

Can you give us the txId of a bitcoin transaction used to represent the entire state?
Post reply on HN