Live data from Hacker News

GPG and Me

thoughtcrime.org

101–110 of 267 posts

Re: GPG and Me

#102

Earlier quoted context omitted.

Back in the 90's I tried to use GPG, and I tried to pay for digital music. They both went roughly the same way. Arguably it was easier to use GPG back then than it is now. Pine was my MUA and I had an easy to find public key. Now I have an iPhone, don't use Linux on my laptop anymore, and make heavy use of messaging products. Here's what I have now that I didn't have then, 2FA. There's an app on my phone that makes i…

>Perhaps this will all change because before Snowden we were blissfully unaware Every time I see this in regards to email, I'm puzzled. Carnivore was known about in the 90s. Then there was the AT&T Room 641A in the 200s. So I don't know how people were unaware that state level actors could tap connections and record email. Second, for this threat model, just forcing and validating TLS on SMTP gets you pretty far, doe…

Re: "You're then mostly trusting your email provider. And without trusting them, we get into user-unfriendly stuff like not being able to forget your password."

Nobody should trust their email provider if they are concerned about the privacy of their email. The Job To Be Done, by an email provider such as gmail/yahoo/hotmail is to act as a mail store, and mta. A user should be able to rely on a local MUA for confidentiality. Admittedly, that shifts the level of trust from the Email Provider to the provider of the MUA software and the Local Hardware, which is why things like OpenBSD/Linux and (hopefully not firmware-tweaked) commodity hardware is so important.

Re: GPG and Me

#103
post #62

>When I receive a GPG encrypted email from a stranger, though, I immediately get the feeling that I don’t want to read it. >the email was written by someone who would voluntarily use GPG. >There just seems to be something particular about people who try GPG and conclude that it’s a realistic path to introducing private communication in their lives for casual correspondence with strangers. Is it just me or is the impl…

I think the implication is that GPG is so pathologically complex, awkward, cumbersome, and broken that getting GPG-encrypted e-mail means it's from someone who's so paranoid/obsessive that they encrypt all e-mail, even to strangers (when possible?) even when the tool is so awful as to discourage the average individual.

>someone who's so paranoid/obsessive that they encrypt all e-mail, even to strangers

That's pretty much what I meant, clearly somebody didn't like me bringing it up. I wonder why. I have to use PGP every day for my job, I don't feel like a paranoid/obsessive, so I resent the implication a little bit. It's a clunky piece of software, but it hasn't caused me nearly as much suffering as Lotus Notes.

Re: GPG and Me

#104

Earlier quoted context omitted.

Do you have any specific criticisms of GPG other than "it's old and it's not popular"? What's your ideal vision of what end-to-end encryption for the common (wo)man should look like other than "not GPG"? Two questions whose answers are nonexistent in your article.

Specific criticisms of GPG: > the working hypothesis for privacy enhancing technology was simple: we’d develop really flexible power tools for ourselves, and then teach everyone to be like us... Instead of developing opinionated software with a simple interface, GPG was written to be as powerful and flexible as possible. It’s up to the user whether the underlying cipher is SERPENT or IDEA or TwoFish I think it's self…

> UX failure leads to user uncertainty or insecure behavior.

I'd say user uncertainty and insecure behavior are, each, sufficient criteria to declare a UX a failure.

Re: GPG and Me

#105
post #86
post #54

Earlier quoted context omitted.

There's no other model than the web-of-trust. And it didn't fail because it's hard to grap (it's really not), it failed because a) almost no one needs it and b) the tech is hard to use. Imagining a world where the web-of-trust was succesful is not hard. It starts with everyone using Outlook instead of gmail. Then imagine Outlook having PGP support builtin. Then imagine in the contacts list, every contact was marked w…

At the risk of being inappropriately snarky, to someone who is somewhat skeptical of WoT-based proposals, this reads like: Step 1: the UI will be a mixture of meaningless and annoying to users, causing them to ignore and misuse it Step 2: mumble mumble... self-healing corruption Step 3: the only reason this hasn't succeeded is that people didn't care enough It's exactly those parts in step 2 where I've historically f…

I think part of the problem that the OP is sort of addressing is that we've spent so much time trying to gloss over the first-line failures of PGP, in terms of even getting a key to begin with let alone giving it to other people, that we don't even know if there are practical solutions to the problems you're listing.

Every tool in this space suffers from the choices PGP implementations have made and asking what your uncle would do if trust conflicts occured when he's going to first be asked if he wants an RSA/RSA, RSA/DSA, DSA sign-only, or RSA sign-only key before he gets there, and then have to figure out what keyserver to send to and then....

Answering these high level UX questions requires having actual users.

Re: GPG and Me

#106
From what I have learned, security/cryptography is about protecting what needs to be protected for as long as is necessary (which is relative to the parties and data involved) - there is no such thing as "absolute" or "perfect" security/cryptography and probably never will be.

Based on that statement, "good enough" is "good enough" relative to the value of what is being protected. From my personal experience, while difficult for use by ordinary users, GPG has proven "good enough" (if not better) for most common business/organizational/personal uses.

That is not to say, that a better alternative/increased ease of use is not possible. Better alternatives are always possible (possibly hard), but it seems such an alternative has not yet presented itself. This leads me to believe that this is in fact an ongoing market and worldwide opportunity for those who have the skills to make alternatives real.

Re: GPG and Me

#107
post #69

Note that the article author is the author of TextSecure http://en.wikipedia.org/wiki/TextSecure It's not surprising that he prefers TextSecure over GPG in the context he explains: "introducing private communication(...) for casual correspondence with strangers." It's obvious that author prefers his chat for that. Still there are scenarios where the GPG wins over chat. But it's also true, most people would make serio…

I don't think he is trying to push the use of text secure over PGP, he has admitted that there isn't a replacement for PGP yet. He is just a forward thinker, hoping for a future where strong encryption is ubiquitous.. and not the state where PGP is today.

Re: GPG and Me

#108

Earlier quoted context omitted.

It's the same as people who voluntarily use Windows. It says something about them, that's all.

I can guess why you're being downvoted, but your comment is ironically correct. It /does/ say something about them! But what that is depends on who you ask. And that, again, says something about /them/. Which says something about the downvoters. Irony everywhere.

People are getting offended, but I could have replaced Windows with almost anything. Our choices say things about us. Getting back to the subject at hand, though, I assume 'moxie meant that people who choose to use GPG for casual conversation must be slightly masochistic and therefore slightly less likely to have something interesting to say.

... just like Windows users ;)

Re: GPG and Me

#109
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

GPG is way, way, way to complex for all but the 0.01% of people who are GPG experts. It's too complex for me - and I've read (and enjoyed) Applied Cryptography.

But, not having used it for a few years, I went to take a look again - list some keys, maybe SMS some friends to exchange fingerprints and sign their keys, etc... - I'm trying to recall what the relationship between PUB, SUB, UID, Key Fingerprints are. And how do I indicate that I trust a key and upload it back up to pgp.mit.edu?

And I consider myself a member of the 0.1% who at least understand the principals behind PGP/Public Keys/Private Keys/Web of Trust, etc...

So - if I'm having trouble understanding this without a couple hours of study, their is Zero chance that the other 99% of the population will ever be able to wrap their heads around the intricacies of PGP. Something else is going to have to replace it.

[EDIT - as an aside, I've spent the last hour trying to do a "gen-key" on my ubuntu host, and been prevented by lack of entropy - and yes, I've tried running tcpdump, tried egrepping every file on the system for a string, etc... Ended up on https://bugs.launchpad.net/ubuntu/+source/gnupg/+bug/706011 and the answer seems to be, "Find a machine that does have entropy, or install a hardware random number generator in your computer."

Please add this to the reasons why normal people never use GPG

Edit-2: It took about 25 minutes, but apparently between find / -type f | xargs grep wontfindme and sudo tcpdump -nnn not port 22, I managed to collect enough entropy to keep gpg moving forward. ]

Re: GPG and Me

#110
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

What would be needed for adoption and ease of use would be for a registry to store public keys and salts... for webmail, a section of the message could be labelled as something like...

    [[SECURE_CONTENT abc@ez.im -> foo@bar.com
        BASE64-CONTENT
        =====
        BASE64-SIGNATURE
    ]]
The a browser or email plugin can then retrieve the public key for abc@ez.im and confirm the body was sent by who it says it was. Then if the user has already connected via the plugin, their private key is used.

For simplicity the registry will do email validation of its' users, it should issue a SALT so that PBKDFx(SALT + email + passphrase) is used to generate the private key... the public key is stored in the registry.

For more control, a given service entry in dns for peer-crypt registry for the given domain can be set as an authority. A distributed system could be used for confirming tokens combined with DNSSEC as a control system for greater availability.

There are flaws with this idea, but it could be something that can be made insanely easy to use, as well as adding a lot of security to email transmission without creating an all new infrastructure, only adding services on top of what exists.

For power users, they could set the public key without salt in the registries, if they wanted to manage their own, instead of relying on the generation mechanism, or to use/keep the same key across different addresses/providers.

Post reply on HN