Live data from Hacker News

GPG and Me

thoughtcrime.org

51–60 of 267 posts

Re: GPG and Me

#51
post #28

GPG is an immense failure from the point of protecting person to person communications. It is largely a success in verifying the identities of the software developers. The entire Debian ecosystem relies on GPG in largely successful ways. Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. It appears the PGP just can't be bootstrapped into modernity from…

> Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. Identity and authentication are the biggest reason that PGP hasn't caught on with non-technical users - the web-of-trust is necessary to do distributed identity and authentication properly (under the current model), and the importance of out-of-band verification can be hard to explain. Authentication…

WoT works well for some things like #bitcoin-otc IRC trading channel but still most users aren't checking sigs.

I like how they wanted to completely remove identifying info and similar signature schemes from signify http://www.tedunangst.com/flak/post/signify

Re: GPG and Me

#52
post #28

GPG is an immense failure from the point of protecting person to person communications. It is largely a success in verifying the identities of the software developers. The entire Debian ecosystem relies on GPG in largely successful ways. Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. It appears the PGP just can't be bootstrapped into modernity from…

> Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. Identity and authentication are the biggest reason that PGP hasn't caught on with non-technical users - the web-of-trust is necessary to do distributed identity and authentication properly (under the current model), and the importance of out-of-band verification can be hard to explain. Authentication…

It isn't clear that we should want PGP to succeed from a communication point of view. It's clear that PGP has succeeded in protecting communications of a some subset of users for the last 20 years. Because of the lack of forward secrecy, it isn't clear that this would scale and how common key theft is.

My opinion is basically GPG for identity and Axolotl for comms.

Re: GPG and Me

#53
How long would it take to vet something new? I don't know a lot about crypto but I get the sense that GPG is the gold standard for now. I agree that the interface is awful (and I feel bad for saying that after having learned of Werner Koch's financial situation) and it needs to be replaced. I wonder if some of the guts can be retained to avoid the bugs that come from starting from scratch?

Re: GPG and Me

#54
post #28

GPG is an immense failure from the point of protecting person to person communications. It is largely a success in verifying the identities of the software developers. The entire Debian ecosystem relies on GPG in largely successful ways. Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. It appears the PGP just can't be bootstrapped into modernity from…

> Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. Identity and authentication are the biggest reason that PGP hasn't caught on with non-technical users - the web-of-trust is necessary to do distributed identity and authentication properly (under the current model), and the importance of out-of-band verification can be hard to explain. Authentication…

There's no other model than the web-of-trust. And it didn't fail because it's hard to grap (it's really not), it failed because a) almost no one needs it and b) the tech is hard to use.

Imagining a world where the web-of-trust was succesful is not hard. It starts with everyone using Outlook instead of gmail. Then imagine Outlook having PGP support builtin. Then imagine in the contacts list, every contact was marked with a color, red, yellow green.

Whenever sending an e-mail to a red contact, Outlook would display a small one liner on top of the compose box "There is no identity information about the contact you are sending an e-mail to". (it doesn't matter that no one knows what that means, it's just a small nag that people understand is negative)

Whenever sending an e-mail to a yellow contact, Outlook would display the following nag line: "You have not verified the identity of the contact you're sending an e-mail to. Click here to resolve".

When the user clicks the line, they'll be asked to call the contact on the phone, or meet with them in person and ask them to compare keys. (Perhaps aided with some fancy tech like NFC or whatever)

Will people ignore the nag line? Yes. Will people click through the dialogs to resolve the nag line without actually verifying? Yes. Does that matter? Not as much as crypto-purists would have you believe.

There's always that uncle, niece or colleague that's going to be anal about it anyway. And if the web of trust is big enough, and the devices enabling the web are communicating, it will be very easy for the web to self-heal whenever corruption arises. Just imagine if whenever someone who purports to be your aunt sends you an e-mail, and your e-mail client automatically checks the key with everyone elses in your family.

The only reason the web-of-trust doesn't work is because it was never adopted and made usable by the important software developers. And that never happened because not enough people cared.

Re: GPG and Me

#55
I don't want GPG to get in the way of better, newer options. But even less do I want to read more about people burned by the incompetent engineering of lesser new alternatives.

Can we just declare a flag day and switch to TextSecure?

Re: GPG and Me

#56
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security.

It's not just that, though. Anyone else with your knowledge but no standing would be scorched for saying what you just said. "Throw away the one thing that has proven to be secure and write our own protocol" doesn't go hand in hand with "serious cryptographers trust what this person is saying."

The truth is probably that either you do this or nobody will.

You should. The world would be better for it.

Re: GPG and Me

#57

As a member of the encrypt-everything clique I have to say, though Moxie has a point, Gnupg is infinitely better than alternative of nothing at all. Until someone comes up with a solution that preserves its power and flexibility and marries it with a functional UX -- I shall keep using it

I kinda like the solution of embedding public keys in email addresses: name+8znBcmtXJ2ZeSn7fWVCGfpQI9HnJH1pNBPK397SGrT8=@gmail.com Sure, you'll never actually tell someone this, but it's short enough to copy/paste.

I like the idea, but you'd be amazed at how many databases only allow 30 character email addresses, or javascript email validators that don't recognize "+" as a legal character.

Re: GPG and Me

#59
>When I receive a GPG encrypted email from a stranger, though, I immediately get the feeling that I don’t want to read it.

>the email was written by someone who would voluntarily use GPG.

>There just seems to be something particular about people who try GPG and conclude that it’s a realistic path to introducing private communication in their lives for casual correspondence with strangers.

Is it just me or is the implication here that anybody who uses PGP is usually a kook of some kind?

Re: GPG and Me

#60
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

Hey Moxie, it intrigues me that the first thing you mention in your post isn't technical or even about UX (which is what most people in this thread are focusing on). Instead, it's that you're starting to dislike reading emails from the kind of person who would "voluntarily use GPG".

I know you said there's no unifying theme to these emails, but can you elaborate? Maybe something about security-obssessed lay people using GPG to send the most trivial of emails? Or something else entirely?

Post reply on HN