Live data from Hacker News

PGP: There’s Life in the Old Dog Yet

blog.whiteout.io

51–60 of 79 posts

Re: PGP: There’s Life in the Old Dog Yet

#51

"We make the client available on all relevant platforms, desktop, Chromebook, Android, iOS, Windows phone." And on the https://whiteout.io/ website: Chromebook, Android, iOS, Web, Windows and Firefox OS. So no Linux version at all??? Isn't Linux a relevant platform?

I'm especially sad to see "desktop" used as a synonym for "Windows".

Re: PGP: There’s Life in the Old Dog Yet

#52

Since Keybase inevitably comes up in these PGP conversations, 2 things in advance: 1. I've really been very slow in letting people into Keybase. The wait time is still 6 months (last night I was letting in people who asked back in August.) But now that we've added HackerNews key proofs, I'll let people in today who notice this post who have more than 1 karma and write "I'm HN: {theirusername}" in the request form. 2.…

Thanks for the opportunity to try out Keybase. Great work. The only question, but really important is: What is Keybase's business model? How will you make your living? It's a great service, I'd love to build upon it (my company does email as a service), but that step requires knowing you'll still be here a few years from now.

Early, while working on Keybase, I answered it here:

https://github.com/keybase/keybase-issues/issues/788

Technically, not a lot has changed. We're still just putting our own money into it. However, we just added 3 people full-time and 1 person part-time, and so our costs have gone up. I'll admit, we only did this when we got an idea that we thought could turn Keybase into a business.

In a few months we'll be launching a tangential idea - more than just a PGP key directory. This product will let you do some neat things with data backup and signed (possibly encrypted) file hosting and message spooling. It has nothing to do with email, but it requires a real PKI. I'll save the specifics for a big announcement, but the pricing model will reflect our costs with room to make money. More per gig than Dropbox and far less than Tarsnap.

Should the "business" fail, we'll be back to where we were when I wrote the above answer.

Re: PGP: There’s Life in the Old Dog Yet

#53
post #35
post #34

Earlier quoted context omitted.

WhatsApp.

WhatsApp fails freedom and arguably security. Let's put things in context. Would you trust WhatsApp to be part of the US nuclear launch chain? Or talkes between the leaders of US, France, China, and North Korea.

No and yes.

The type of encryption used in whatsapp is not something I want to authenticate in anything that has to be dormant and used in an emergency without a network, but that doesn't mean it is bad crypto.

Yes, why not? You still need to ensure that the people involved with whatsapp can be trusted, but even the NSA can't do that in every case (ie Snowdon).

Re: PGP: There’s Life in the Old Dog Yet

#54
post #32
post #30

Earlier quoted context omitted.

I hadn't really heard about keybase yet, but does it solve the only problem worth solving in encryption? Does it allow me to take any email address and give me back a private key that only the recipient can use? If I wanted to know which public key to use I would just look at the recipients public website or ask that person through a phone. The problem is that people don't create keys because nobody ever send them an…

Easier PGP programs would increase the use of encryption, especially post-Snowden. I've walked people through using GPG4WIN/Kleopatra and it took a good half hour of explaining how everything works. People care about privacy, but unfortunately not enough to go through the hassle of manually encrypting everything.

Not sure I understand what you mean. For some family members I set up Thunderbird+Enigmail, which was very quick including keypair generation.

Now they communicate with me always encrypted, automatically. They don't have to know any details about encryption, except that they occationally have to type in their password.

Re: PGP: There’s Life in the Old Dog Yet

#55
Would you trust your life on a protocal such as HTTPS?

How often is https broken? It seems like every six weeks OpenSSL comes out with a new advisory full of vulnerabilities. I'm assuming that the world powers out there have zero days in OpenSSL, they attack SSL and VPNs all day long. People will be harmed if they trust HTTPS to secure their correspondence.

It is great that you're trying to give PGP a new life, but you're weakening it by using a vulnerable protocol with it. The weakest link will always break first.

Re: PGP: There’s Life in the Old Dog Yet

#56

Since Keybase inevitably comes up in these PGP conversations, 2 things in advance: 1. I've really been very slow in letting people into Keybase. The wait time is still 6 months (last night I was letting in people who asked back in August.) But now that we've added HackerNews key proofs, I'll let people in today who notice this post who have more than 1 karma and write "I'm HN: {theirusername}" in the request form. 2.…

Just wanted to say thanks for the chance to try it out. Looks pretty awesome!

Re: PGP: There’s Life in the Old Dog Yet

#57
post #5

Quoting Dan Geer: "Convenience, freedom, security - choose two." Solid cryptography concepts were never easy to implement and use. My main problem lies not with the Gnu/PG or PGP software implementations, but with the actual platforms. Do I trust my iPhone/Android/public internet cafe computer/the family computer? Is it compromised? What about your computer manufacturer? Lenovo, perhaps? Or Apple? The problem of info…

Choose two? How do I pick security and convenience without freedom? I can't think of any way giving up freedom makes those easier. Blind trust can make me ignore security problems, but I can have blind trust and freedom, or lack of freedom without blind trust.

I feel like "security or convenience" is a better representation of the choice, even if it's not as cute. Freedom is off to the side.

Re: PGP: There’s Life in the Old Dog Yet

#58

It's actually quite simple. PGP/GPG is the equivalent of the S in HTTPS. It's a trust model + ciphersuite + tools and libraries for using it. Would you ask your users to use TLS directly? No, you would not. Would you be surprised if the users hated using TLS directly? Nope. What PGP/GPG actually needs is a nice UI. What's been holding it back is webmail. PGP and webmail are incompatible. Now that mobile is starting t…

The problem is that, on the whole, users simply don't care. They have more important things to worry about than email encryption (you know, stuff like spouse, kids, mortgage, partying, etc). The only way I can see end-to-end crypto really being adopted is if it's turned on by default everywhere. The selling point can't be the security, because people don't care about security -- the selling point has to be something…

Which is why I proposed that UI: it works automatically. While using the system, it simply indicates to you as you compose the message "Yes, the email address you are sending mail to belongs to the person you intend to message" or "No, that email address belongs to someone else" or "This is a brand new email address." This way when you are emailing your lawyer to set up a will, or you email your accountant with your tax info, you can be sure that (a) you are emailing just the right person and (b) that only they can read the communication.

While setting up the system, you are simply required to link your identity. Twitter, Facebook, LinkedIn, GMail, HN, the government all should allow you to easily link your identity. This should be a normal part of your account creation (this can tie in nicely with another change: getting rid of passwords and using a browser UI for identifying yourself a la Persona, but PGP based). Basically when signing up for Twitter, it should optionally let you upload one of your public keys (via a nice browser UI no less). Twitter (Facebook, GMail, etc.) would then expose a nice API for querying by public key fingerprint: "Who has 0xDEADBEEF?" => "@DeadBeef". Revocation, key updates, all that should be automatic: you revoke your public key and issue a replacement, all your services update automatically.

This is the point where lots of people will raise concerns about privacy: "This means Twitter now must have access to my GMail account! WTF?!". No. This process must be voluntary and optional. If you want to have 200 different identities online, go for it. I don't care to know your real name, I just care to know that I am talking only to the person I intend to talk to. Think emailing a well known developer on GitHub, having never met them. You don't need their real name, you are only interested in them in so far as they publish OSS on GitHub. This allows you to prove that github.com/example is @example on Twitter, example@example.com, example@gmail.com, and HN user "example".

And the benefit to "regular Joe" is that when he emails his accountant, he can now send his credit card number and SSN without fear of eavesdropping.

Re: PGP: There’s Life in the Old Dog Yet

#59
post #46
post #43

Earlier quoted context omitted.

> Yes, but it's cryptographically well understood not to provide the properties we need. If you're talking about perfect forward secrecy, surely that's fundamentally impossible for a protocol that is both asynchronous and decentralized? If one party can only send a single async message to another, then that message necessarily must be decryptable by that second party using only what that second party knows, and you l…

https://whispersystems.org/blog/asynchronous-security/ https://whispersystems.org/blog/advanced-ratcheting/ https://whispersystems.org/blog/simplifying-otr-deniability/

> With the initial key exchange out of the way, both parties can then continue communicating with an OTR-style protocol as usual. Since the server never hands out the same prekey twice (and the client would never accept the same prekey twice), we are able to provide forward secrecy in a fully asynchronous environment.

So, my laptop is off-line, and I have access to a recipients public key. How do I encrypt my message, before moving it to a machine that's on-line for sending via smtp?

This isn't really asynchronous in the sense that email is (stop-forwards-stop-forward). Nor does it appear to work for writing and encrypting an sms while on an air-plane (the message will only be encrypted when the pre-key can be retrieved).

It doesn't seem quite fair to claim (or rather imply) that the scheme does for email what pgp does.

It also carries more state around (on the "server" and on the "client") so it's not decentralized. It might be closer to pgp than classic otr, but it's not really a replacement for pgp as far as I can tell.

Re: PGP: There’s Life in the Old Dog Yet

#60

"We make the client available on all relevant platforms, desktop, Chromebook, Android, iOS, Windows phone." And on the https://whiteout.io/ website: Chromebook, Android, iOS, Web, Windows and Firefox OS. So no Linux version at all??? Isn't Linux a relevant platform?

This is why it matters that we say GNU/Linux, not just "Linux". Android and Chromebook run the Linux kernel. As well as Firefox OS AFAIK.
Post reply on HN