Live data from Hacker News

GPG and Me

thoughtcrime.org

141–150 of 267 posts

Re: GPG and Me

#141
post #50
post #28

GPG is an immense failure from the point of protecting person to person communications. It is largely a success in verifying the identities of the software developers. The entire Debian ecosystem relies on GPG in largely successful ways. Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. It appears the PGP just can't be bootstrapped into modernity from…

GPG still could be much better for those applications. For example, it is still impossible to do GPG multi-sig (e.g. have the application developer and the distribution release manager sign off on the binaries).

Can't you just create two detached signatures?

Re: GPG and Me

#142
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

I am - roughly - a GPG fan. I've done classes on it, used it at work and at home, etc.

GPG is a terrible UX. Accidental use of GPG tends to fail open, and insecurity results. Futzing with different keys, rotating them, retracting them, etc, are grievous. I can't reencrypt old stuff to new stuff (e.g., a pw database) without spending a good deal of time thinking about attacks, file safety, etc.

I'm really a distributed encrypted email fan, I guess. I want to securely communicate over email to my friends and family, without having to do the GPG dance.

Re: GPG and Me

#144
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security. It's not just that, though. Anyone else with your knowledge but no standing would be s…

Go through my comment history. How many comments do you see? A handful? Yup. The reason there are so few is because, I only reply to comments I wholeheartedly agree with. And this is one of them.

Re: GPG and Me

#145
post #18

Earlier quoted context omitted.

faint? I'd rather read 100 pages of man than die. Seems like a meager price to ensure another 70 years of life.

The point is when "virtually everything" is better than death or torture, it's not saying much when that's how you praise using GPG.

[deleted]

Re: GPG and Me

#146
post #137

Earlier quoted context omitted.

>We could try to slap a GUI on top of it, but I don't believe great products are made that way. I'm right there with you on that one. So is most of HN I imagine. But the Apple ][ really brought the PC home for so many more people than it's competitors purely because of it's relatively simple GUI. Command prompts scare the average user.

The Apple ][ booted to the commandline, as did the ][+, //e, and //c.

At least the //e could boot to a disk without any interaction with the command line.

I guess that's why I will always be a C=> fan.

Re: GPG and Me

#147
post #132

Earlier quoted context omitted.

You say "Redphone? Whisper? and various other projects - while very cool - didn't achieve even as much popularity as GnuPG" The Axolotl protocol that was created for Whisper System's TextSecure is now used, by default, by Cyanogenmod (10 million users) and the Android version of WhatsApp (more than 500 million installs from the play store). I'd say Moxie's tech has been pretty widely adopted.

When can I have a compatible FOSS desktop client? I don't do 100% of my communications from my phone, and I never will.

If you can't do it on desktop, you can't do it at all. Mainly because some of us have real work to do.

If the only "usable" implementation is on a hard-to-physically-secure mobile device that uses a tonne of different uncontrolled network access points a day -- that's not really an option now, is it?

Re: GPG and Me

#148
post #90

Earlier quoted context omitted.

What do you think that looks like, though? Is it TextSecure on the desktop, with file attachments? Is it Pond? Is it just email, but with a different crypto layer? I feel like a lot of the things GPG aims to do are fundamentally hard. It's not the technology that sucks, it's the problem . I completely agree that the answer will come from thinking about user interactions first, but I'm not sure that the solution will…

I don't have a definite answer. There's the path we're executing on at Open Whisper Systems, but there are a bunch of other projects working in this area as well (Mailpile, LEAP, etc). I think the problems are solvable, but only if we have a different design approach. So when I see projects trying not-PGP, I'm interested. When I see projects building on PGP, I'm less interested.

I'll take the opportunity to say that it saddens me that I still can not communicate using TextSecure with iOS users. It's been almost two years[1] since iOS support was "promised". TS is great, but we need to be able to communicate with iOS users.

[1] https://whispersystems.org/blog/sure/

Re: GPG and Me

#149
post #15

>When I receive a GPG encrypted email from a stranger, though, I immediately get the feeling that I don’t want to read it. This is an interesting case where a barrier to entry makes discourse less valuable. Perhaps the barrier makes people feel like they have to prepare a short speech in order to make the effort worthwhile. I certainly would rather converse with most people than listen to one minute speeches from the…

If you ready on, you'll see that his gripe isn't with the effort put into decrypting, but the subset of people who voluntarily use GPG.

Ironically unsaid:

"People like myself for twenty years and nothing to sell."

Re: GPG and Me

#150
> When I receive a GPG encrypted email from a stranger, though, I immediately get the feeling that I don’t want to read it.

I don't understand why. Did I glance over it, or is it not in the article?

When I receive GPG encrypted email, I only have to enter my password and it gets decrypted. Simple as that. Same as when starting me email client, then too I have to enter a password to decrypt the login for the server. It takes only a moment really.

I don't receive that much email from strangers anyway, but the times I get GPG encrypted email from a stranger it's never spam, so it's surely worth the approximately three seconds to enter that password.

(For the curious, I use Thunderbird with Enigmail and kgpg as front-end to GnuPG.)

Post reply on HN