GPG is an immense failure from the point of protecting person to person communications. It is largely a success in verifying the identities of the software developers. The entire Debian ecosystem relies on GPG in largely successful ways. Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. It appears the PGP just can't be bootstrapped into modernity from…
GPG still could be much better for those applications. For example, it is still impossible to do GPG multi-sig (e.g. have the application developer and the distribution release manager sign off on the binaries).
GPG and Me
141–150 of 267 posts
Re: GPG and Me
#142A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…
GPG is a terrible UX. Accidental use of GPG tends to fail open, and insecurity results. Futzing with different keys, rotating them, retracting them, etc, are grievous. I can't reencrypt old stuff to new stuff (e.g., a pw database) without spending a good deal of time thinking about attacks, file safety, etc.
I'm really a distributed encrypted email fan, I guess. I want to securely communicate over email to my friends and family, without having to do the GPG dance.
Re: GPG and Me
#143Also, to be fair, it's used widely by many infosec researchers/vendors/IC folks who know how it's done.
Re: GPG and Me
#144A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…
You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security. It's not just that, though. Anyone else with your knowledge but no standing would be s…
Re: GPG and Me
#145Earlier quoted context omitted.
faint? I'd rather read 100 pages of man than die. Seems like a meager price to ensure another 70 years of life.
The point is when "virtually everything" is better than death or torture, it's not saying much when that's how you praise using GPG.
Re: GPG and Me
#146Earlier quoted context omitted.
>We could try to slap a GUI on top of it, but I don't believe great products are made that way. I'm right there with you on that one. So is most of HN I imagine. But the Apple ][ really brought the PC home for so many more people than it's competitors purely because of it's relatively simple GUI. Command prompts scare the average user.
The Apple ][ booted to the commandline, as did the ][+, //e, and //c.
I guess that's why I will always be a C=> fan.
Re: GPG and Me
#147Earlier quoted context omitted.
You say "Redphone? Whisper? and various other projects - while very cool - didn't achieve even as much popularity as GnuPG" The Axolotl protocol that was created for Whisper System's TextSecure is now used, by default, by Cyanogenmod (10 million users) and the Android version of WhatsApp (more than 500 million installs from the play store). I'd say Moxie's tech has been pretty widely adopted.
When can I have a compatible FOSS desktop client? I don't do 100% of my communications from my phone, and I never will.
If the only "usable" implementation is on a hard-to-physically-secure mobile device that uses a tonne of different uncontrolled network access points a day -- that's not really an option now, is it?
Re: GPG and Me
#148Earlier quoted context omitted.
What do you think that looks like, though? Is it TextSecure on the desktop, with file attachments? Is it Pond? Is it just email, but with a different crypto layer? I feel like a lot of the things GPG aims to do are fundamentally hard. It's not the technology that sucks, it's the problem . I completely agree that the answer will come from thinking about user interactions first, but I'm not sure that the solution will…
I don't have a definite answer. There's the path we're executing on at Open Whisper Systems, but there are a bunch of other projects working in this area as well (Mailpile, LEAP, etc). I think the problems are solvable, but only if we have a different design approach. So when I see projects trying not-PGP, I'm interested. When I see projects building on PGP, I'm less interested.
Re: GPG and Me
#149>When I receive a GPG encrypted email from a stranger, though, I immediately get the feeling that I don’t want to read it. This is an interesting case where a barrier to entry makes discourse less valuable. Perhaps the barrier makes people feel like they have to prepare a short speech in order to make the effort worthwhile. I certainly would rather converse with most people than listen to one minute speeches from the…
If you ready on, you'll see that his gripe isn't with the effort put into decrypting, but the subset of people who voluntarily use GPG.
"People like myself for twenty years and nothing to sell."
Re: GPG and Me
#150I don't understand why. Did I glance over it, or is it not in the article?
When I receive GPG encrypted email, I only have to enter my password and it gets decrypted. Simple as that. Same as when starting me email client, then too I have to enter a password to decrypt the login for the server. It takes only a moment really.
I don't receive that much email from strangers anyway, but the times I get GPG encrypted email from a stranger it's never spam, so it's surely worth the approximately three seconds to enter that password.
(For the curious, I use Thunderbird with Enigmail and kgpg as front-end to GnuPG.)