Quoting Dan Geer: "Convenience, freedom, security - choose two." Solid cryptography concepts were never easy to implement and use. My main problem lies not with the Gnu/PG or PGP software implementations, but with the actual platforms. Do I trust my iPhone/Android/public internet cafe computer/the family computer? Is it compromised? What about your computer manufacturer? Lenovo, perhaps? Or Apple? The problem of info…
PGP: There’s Life in the Old Dog Yet
31–40 of 79 posts
Re: PGP: There’s Life in the Old Dog Yet
#32Since Keybase inevitably comes up in these PGP conversations, 2 things in advance: 1. I've really been very slow in letting people into Keybase. The wait time is still 6 months (last night I was letting in people who asked back in August.) But now that we've added HackerNews key proofs, I'll let people in today who notice this post who have more than 1 karma and write "I'm HN: {theirusername}" in the request form. 2.…
I hadn't really heard about keybase yet, but does it solve the only problem worth solving in encryption? Does it allow me to take any email address and give me back a private key that only the recipient can use? If I wanted to know which public key to use I would just look at the recipients public website or ask that person through a phone. The problem is that people don't create keys because nobody ever send them an…
Re: PGP: There’s Life in the Old Dog Yet
#33Quoting Dan Geer: "Convenience, freedom, security - choose two." Solid cryptography concepts were never easy to implement and use. My main problem lies not with the Gnu/PG or PGP software implementations, but with the actual platforms. Do I trust my iPhone/Android/public internet cafe computer/the family computer? Is it compromised? What about your computer manufacturer? Lenovo, perhaps? Or Apple? The problem of info…
I probably shouldn't go around and disagree with quotes from people I have never heard about, but there is no law that means encryption has to be ackward, user-unfriendly or badly designed.
HTTPS: You can give up freedom and some security for convenience of 3rd party registrars! You can roll your own which is less convenient and likely less secure… Not really sure of the 3rd option here.
Re: PGP: There’s Life in the Old Dog Yet
#34Earlier quoted context omitted.
I probably shouldn't go around and disagree with quotes from people I have never heard about, but there is no law that means encryption has to be ackward, user-unfriendly or badly designed.
Can you name a single counterexample? HTTPS: You can give up freedom and some security for convenience of 3rd party registrars! You can roll your own which is less convenient and likely less secure… Not really sure of the 3rd option here.
Re: PGP: There’s Life in the Old Dog Yet
#35Earlier quoted context omitted.
Can you name a single counterexample? HTTPS: You can give up freedom and some security for convenience of 3rd party registrars! You can roll your own which is less convenient and likely less secure… Not really sure of the 3rd option here.
WhatsApp.
Let's put things in context. Would you trust WhatsApp to be part of the US nuclear launch chain? Or talkes between the leaders of US, France, China, and North Korea.
Re: PGP: There’s Life in the Old Dog Yet
#36That leaves these points for PGP:
> It’s been around for a long time, so it’s cryptographically well understood.
Yes, but it's cryptographically well understood not to provide the properties we need.
> There are a variety of implementations and there is a small but vibrant and highly committed developer community. > A small but active and committed user community.
Small can't be emphasized enough, and this is the most important part to me. I think people have a tendency to look at PGP and conclude that while it might be painful, we have to put up with it for backwards compatibility. The truth is that it's a protocol with few contemporary redeeming qualities, and an active user base of ~50k. So why bother with backwards compatibility?
Re: PGP: There’s Life in the Old Dog Yet
#37I'm not really positioning TextSecure as a secure mail solution, but this article says that the TextSecure protocol can't support asynchronous operations or federated namespaces. To clarify, that's incorrect, the TextSecure protocol was actually designed from the ground up for asynchronous communication, and is designed to support a federated namespace: https://whispersystems.org/blog/asynchronous-security/ That leav…
Re: PGP: There’s Life in the Old Dog Yet
#38Since Keybase inevitably comes up in these PGP conversations, 2 things in advance: 1. I've really been very slow in letting people into Keybase. The wait time is still 6 months (last night I was letting in people who asked back in August.) But now that we've added HackerNews key proofs, I'll let people in today who notice this post who have more than 1 karma and write "I'm HN: {theirusername}" in the request form. 2.…
I hadn't really heard about keybase yet, but does it solve the only problem worth solving in encryption? Does it allow me to take any email address and give me back a private key that only the recipient can use? If I wanted to know which public key to use I would just look at the recipients public website or ask that person through a phone. The problem is that people don't create keys because nobody ever send them an…
Re: PGP: There’s Life in the Old Dog Yet
#39Since Keybase inevitably comes up in these PGP conversations, 2 things in advance: 1. I've really been very slow in letting people into Keybase. The wait time is still 6 months (last night I was letting in people who asked back in August.) But now that we've added HackerNews key proofs, I'll let people in today who notice this post who have more than 1 karma and write "I'm HN: {theirusername}" in the request form. 2.…
I hadn't really heard about keybase yet, but does it solve the only problem worth solving in encryption? Does it allow me to take any email address and give me back a private key that only the recipient can use? If I wanted to know which public key to use I would just look at the recipients public website or ask that person through a phone. The problem is that people don't create keys because nobody ever send them an…
Re: PGP: There’s Life in the Old Dog Yet
#40Since Keybase inevitably comes up in these PGP conversations, 2 things in advance: 1. I've really been very slow in letting people into Keybase. The wait time is still 6 months (last night I was letting in people who asked back in August.) But now that we've added HackerNews key proofs, I'll let people in today who notice this post who have more than 1 karma and write "I'm HN: {theirusername}" in the request form. 2.…
The only question, but really important is: What is Keybase's business model? How will you make your living? It's a great service, I'd love to build upon it (my company does email as a service), but that step requires knowing you'll still be here a few years from now.