Live data from Hacker News

GPG and Me

thoughtcrime.org

11–20 of 267 posts

Re: GPG and Me

#11
Is there a list of credible web of trust implementations with installed bases? Is there anything on that list using new Html5 crypto plus IETF JOSE?

Re: GPG and Me

#12
I am curious as to to know what mail clients people are using with GPG. In OSX I am not a big fan of the native mail client at all but it seems thats the only approach if you want to use GPG. I am currently on a quest to find a decent mail client that looks good and works well and I am currently trialling Airmail 2 but its GPG support is buggy at best.

Re: GPG and Me

#13

The old adage is that perfect is the enemy of good enough, but the author is claiming that GPG isn't even good enough. I have to somewhat disagree. While the ideal product in this space would be as easy to use as clicking a 'Like' button, and just as ubiquitous, GPG works well enough for now. The most sensitive use case for GPG has to be sending correspondence that, if decrypted, could put you in severe physical dang…

You've missed out "Use GPG, but perform one of many steps wrongly, and thus face torture or death".

See also "deanonymizing alt.anonymous.messages"

https://ritter.vg/blog-deanonymizing_amm.html

Re: GPG and Me

#14

I am curious as to to know what mail clients people are using with GPG. In OSX I am not a big fan of the native mail client at all but it seems thats the only approach if you want to use GPG. I am currently on a quest to find a decent mail client that looks good and works well and I am currently trialling Airmail 2 but its GPG support is buggy at best.

I have been using Thunderbird (with Enigmail plugin) for over a decade now. Never had any issues.

Re: GPG and Me

#15
>When I receive a GPG encrypted email from a stranger, though, I immediately get the feeling that I don’t want to read it.

This is an interesting case where a barrier to entry makes discourse less valuable. Perhaps the barrier makes people feel like they have to prepare a short speech in order to make the effort worthwhile. I certainly would rather converse with most people than listen to one minute speeches from them.

Re: GPG and Me

#16
post #7

Earlier quoted context omitted.

Using X is preferable to death or torture. That's what I call faint praise.

faint? I'd rather read 100 pages of man than die. Seems like a meager price to ensure another 70 years of life.

http://en.wikipedia.org/wiki/Damning_with_faint_praise

Re: GPG and Me

#17
This is a very interesting point, all the more interesting that it takes someone with Moxie's clout for the message to come out.

I've been in and out of the "GPG everything!" group over the years, and I definitely agree that GPG is a pain to use. I always figured this was because of the lack of proper frontends, and was hoping for the major influx of funding a couple weeks back would help it make progress in usability and infrastructure, but Moxie says that it's obsolete at its core.

But if we're to replace it, the replacement has to not only be at least as secure, but also standardized and embeddable. A webapp or Chrome extension (which Google's End-to-End is) won't make the cut.

Re: GPG and Me

#18
post #7

Earlier quoted context omitted.

Using X is preferable to death or torture. That's what I call faint praise.

faint? I'd rather read 100 pages of man than die. Seems like a meager price to ensure another 70 years of life.

The point is when "virtually everything" is better than death or torture, it's not saying much when that's how you praise using GPG.

Re: GPG and Me

#19
It seems that the biggest problem with encryption in general is that of incentives. Great UX takes lots of design and iteration, which means someone has to pay for all those designers and front end devs. However, when you want good encryption, user experience always comes after security, which means you spend the majority of your resources on the security, not the design. So, we end up with great security and terrible user experience. It's (painfully) rational.

Sure, every once in a while you have good security luck out and land a great designer (TextSecure), but that's extremely rare. The vast majority of security teams don't value design as much as security because they don't have the incentive to.

So how do we fix the incentives? Can we? Should we?

Re: GPG and Me

#20

The old adage is that perfect is the enemy of good enough, but the author is claiming that GPG isn't even good enough. I have to somewhat disagree. While the ideal product in this space would be as easy to use as clicking a 'Like' button, and just as ubiquitous, GPG works well enough for now. The most sensitive use case for GPG has to be sending correspondence that, if decrypted, could put you in severe physical dang…

I don't think that the author ever disputed that GPG is a highly secure system when functioning, or that it is "the best we have". Certainly it's the best we have, and that highlights the sad state of affairs.

I think a lot of engineers make the mistake that regular people will be so won over by a new technology that they'll learn it as well as the engineers do. That isn't how it works. So far we still haven't gotten regular people to learn programming, though more people program than ever before.

Humans like simple. This is not a flaw. Software can do anything, and it is written for us. We should not have to learn a bunch of arcane commands, skills, and concepts unless there is no technical way around this.

Ideal encryption would have a quick initial setup, and then each message would have a sticky button for "encrypt?". Then whatever is required in the backend does what it needs to do.

Complex software that gets the job done is much, much worse than simple software that gets the job done. Unless things get so oversimplified that there is no way to verify correct operation. I agree that people need to learn about encryption, but there's a middle ground between no knowledge and knowing enough about it to use GPG.

Post reply on HN