Live data from Hacker News

GPG and Me

thoughtcrime.org

251–260 of 267 posts

Re: GPG and Me

#251
post #132

Earlier quoted context omitted.

When can I have a compatible FOSS desktop client? I don't do 100% of my communications from my phone, and I never will.

If you can't do it on desktop, you can't do it at all. Mainly because some of us have real work to do. If the only "usable" implementation is on a hard-to-physically-secure mobile device that uses a tonne of different uncontrolled network access points a day -- that's not really an option now, is it?

I feel you're missing open whisper systems' target audience. If you've seen how regular people use computers, their phone is the most secure device a normal person owns. Not the most secure if you're worried about targeted attack, but the best place to put a dent in cheap dragnet surveillance :)

Re: GPG and Me

#252
post #82

Articles (and the attendant discussions) like this are incredibly useful for me. I really appreciate HN for things like this. Recently signed up for keybase to check it out. Read critiques (mostly negative) but jumped in anyway as I am hungry for something like it. I do not have a deep grasp of the arguments but I see the 'lipstick on a pig' criticism of slapping a gui on an aging infrastructure. The practical proble…

Just signed up for keybase and in the same position. Don't know anyone on the service to actually use it with.

Interested in testing it out with me?

Re: GPG and Me

#253

Earlier quoted context omitted.

Do you have any specific criticisms of GPG other than "it's old and it's not popular"? What's your ideal vision of what end-to-end encryption for the common (wo)man should look like other than "not GPG"? Two questions whose answers are nonexistent in your article.

Specific criticisms of GPG: > the working hypothesis for privacy enhancing technology was simple: we’d develop really flexible power tools for ourselves, and then teach everyone to be like us... Instead of developing opinionated software with a simple interface, GPG was written to be as powerful and flexible as possible. It’s up to the user whether the underlying cipher is SERPENT or IDEA or TwoFish I think it's self…

Thanks; for the first question, I suppose I should have read more carefully.

The second question, however, still isn't adequately answered; "we should be thinking about interactions" and "we should use modern things" are two of the most vague answers possible.

Re: GPG and Me

#254
post #173

Earlier quoted context omitted.

It's one thing to recognize the limitations of GPG. I think we all do. It's another to declare it an abject failure and continue to use it and complain. Go generate a revocation certificate and push it to the global pool. You'll stop getting those disappointing emails. But seriously, go build something better. I fucking dare you. We'd all be better off for it if you really did.

He does build something: https://whispersystems.org/

Whether or not that something is better, however, depends very much on the use case. RedPhone and TextSecure are designed for very specific use cases (phone calls and text messages, respectively), whereas GnuPG is designed to be general-purpose and universal regardless of use case. Most jarringly, neither of those programs address email or file encryption/verification, and thus do nothing in GnuPG's primary realms of usage; by comparing them, you're basically comparing apples and crowbars.

Re: GPG and Me

#255
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security. It's not just that, though. Anyone else with your knowledge but no standing would be s…

> You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security.

This attitude is why GnuPG (and other PGP implementations) are in a position to be criticized by the Moxies of the world. Is there some particular reason why anybody outside of some recognized elite should be discouraged from at least trying to create a better, improved system? Yeah, they'll probably fail in a lot of cases, but if the world really wants a modern, easy-to-use alternative to PGP (a real alternative, not use-case-specific alternatives like RedPhone and TextSecure; encrypted/signed email is still a valid use case that both those things blissfully ignore, by the way), this sort of attitude - that anyone outside of a select few rightfully deserves to be scolded for trying to make better crypto - is lethally toxic to that goal.

Re: GPG and Me

#256

Earlier quoted context omitted.

You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security. It's not just that, though. Anyone else with your knowledge but no standing would be s…

> You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security. This attitude is why GnuPG (and other PGP implementations) are in a position to be c…

Yes, there is a reason to discourage those people.

In between the time that a cryptographically illiterate developer releases their MVP 1.0 version and the time that it's discovered that their cryptography is fundamentally flawed --- a window of time that can stretch on for years --- actual people will rely on the tool for their security, not realizing that serious adversaries are reading their messages.

Most new cryptosystems --- a cryptosystem being "anything that uses a cipher, including when the cipher is simply AES --- are terribly broken.

Search for [decryptocat] for an extremely good example of what I'm talking about.

Developers who are new to cryptography that want to learn more about it and eventually use it in their own systems should start by learning how to exploit broken cryptography. If you can't exploit an RSA padding oracle, you shouldn't be designing systems that use public key cryptography. If you can't exploit a CTR nonce stutter, you shouldn't be using block crypto.

Developers who don't want to learn cryptography should work on improving the UX (UI and workflow) of existing cryptosystems. PGP could sure use some help, but even if you don't want to help with PGP, there's a huge green field of work to be done on browser TLS trust and CA user interface. Just as one example.

Re: GPG and Me

#257
post #82

Articles (and the attendant discussions) like this are incredibly useful for me. I really appreciate HN for things like this. Recently signed up for keybase to check it out. Read critiques (mostly negative) but jumped in anyway as I am hungry for something like it. I do not have a deep grasp of the arguments but I see the 'lipstick on a pig' criticism of slapping a gui on an aging infrastructure. The practical proble…

Just signed up for keybase and in the same position. Don't know anyone on the service to actually use it with. Interested in testing it out with me?

If no one's taken you up on that, here's a message for you:

-----BEGIN PGP MESSAGE----- Version: Keybase OpenPGP v2.0.7 Comment: https://keybase.io/crypto

wcFMA5S7hsT55Ka3AQ/+K3YTd9aLF70PcDuDzUSBwt42I4UJdASvSzU9ljJZhxmh xn/XgzfuPVEqi75jhI20SfKJetR867leishDNU/XrynFCyJcr0ax6Q6BQes/w94d ErmBchxcYwFumB0i0tWMygmCUKgpL7W5bC26gB4AUdoPhhdJQnHYwiLvEv+e1G6I wFEA2/WzJlB+K+4v782zF7RhZaTA6OXl0noL6Nsoi2V/yufD5qKVnolx3RSHzdTd 1bSdS7lTCIQzvDmuLYvkophBL6Vb6Qa8IdwkLVxt+akr/W4oOxLaEE14HxS05OTO bN0R5yXzNNI7RWfU4cB3JKUMSKLGB4cBf+jEj1WyGCm04/9I1XgnNqFULE4RfHwG t8mqS1oeetfKlrzEx7NkXVn7mvITiYUzeH+M/DaTlnp5+Nb1FgQK1U54emIgEpmR qaG9JYDxZBtmBQ2gb3RtXndZFWQh7YifqaDFsUkJl4cdjXZ69WccvFRr+Vr3Ow1O m19lrHAFj4XZtsS9C1PNBejpdcfANoWjG+9Eitd6iliAo4nCG9jUi/6mIWRuamcs OS2uAAWMe1ZrfhwwU/x2+/QM6eGKU43DBLy9lmyFj2UgZKW1UokQg7iAp3Wd0f+Z SBEXNFsM3rPoYVb29boUcJtkA4CpArH36kIBv45A9u1c14uTUVRreGeLe1pqrsXB wEwD5S1urhQzgBEBCACk1jR8gIaMRKCsl7ofIjGr8PrrOYVCkNtpWjGsNnq+SFkG SUUekwzB0MfRVSdrkfVk/7Axrm0YGWqW9v12aNrrRLe8Vs/VJU9r2RRBgI164YbI UDxlGBJZhNnG1BxPVt1en1nH9ceEw4yq15giSxRMOhtlmpdv6Y0HIWzhnAb+Hc68 rxFq74j2wEfkHkIYJV7cOZtXy9WF0WHVgi0wIyiDHvV84KTO5HUv2qA1uJiqt3UU phq+lmFr3DzH7mcz2vLBW8r1AeFOd9VtRNVPkLEaVIjlCPGTYgr0hCfUX+JSf6PN 1VSRdogjcBu5Cqui60Fz9RKQvPCpX0NAUJpEZ30H0sEQATqCbZ/PF7nEqVHAOoH4 FK+Q6cR4+8iArPnUjr0lP0KWaQDJBghbYqQ8aUX37NUJaih7wae1b5WyBBCtwilI GowCJXwiD0kd7xUns61MhNDSn2K2ZPifHptJcv5QvODLkoJSHP4ylqCa9SrzyFNR gpRk3I31NIxZd7M5PT8fepQ75qTOgZ/v8ZTEd0HbPpjjRNJ3hMtIo7nmzPk54aD7 182jBWbXhiYiTTYEExnGwq+uDHoQjtGGBQzJegqeNex/q3Ba7Lf5RCbfFXQy3aDj JGRY6rZCQFbtcym2fjxeT9lRmHHeXA400zeLXgbqmmAKAcQwBtQQIF4Cg/cDNItN 6o5Jov0+pAm/NKKRWIXGJErGXsi0iTqJyl0anasbrQH6dnEXNbbMslIOtDl9CtKR N5Y+x+vJJKsOQaT6dJmQHZ19RxW4tickEr6zEu6IhB8ooMGMAjdq+tpRAF4+qKyK /yWUTIpp14deORe3aK7Hu0mA6H9dxDfwNwvat3Iv8R7YbsILdp7sFBPBlVLRLoBp BlYe7Eqroe7dCLg+v9Uw3Hpbu0yp3/BY64H3Qj9f7X3HQ+6nHQ0oQNS6XcwvJnKo JTV8lO263q0P7+Pti05SSs4= =gLgR -----END PGP MESSAGE-----

Re: GPG and Me

#258

Earlier quoted context omitted.

> You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security. This attitude is why GnuPG (and other PGP implementations) are in a position to be c…

Yes, there is a reason to discourage those people. In between the time that a cryptographically illiterate developer releases their MVP 1.0 version and the time that it's discovered that their cryptography is fundamentally flawed --- a window of time that can stretch on for years --- actual people will rely on the tool for their security, not realizing that serious adversaries are reading their messages. Most new cry…

My point is that this attitude of "only people who have proven themselves as cryptography geniuses may dare to think about thinking about cryptographic protocols" also discourages the potential UX/UI/workflow/etc. programmers from participating, since it gives the impression that their contributions will never be "good enough" to be accepted. It also discourages potential developers of the crypto algorithms and protocols themselves from participating, even if they have gone through the (in your opinion) requisite experience of learning how to break existing cryptosystems, because of the fear that they'll just be burned at the stake by the rabid likes of Hacker News and Slashdot for daring to suggest anything new (these are the sorts of cryptographic programmers I'm talking about, not some "badass rockstar ninja" Macbook-toting YCombinator-funded Ruby.js hipsters manufactured in the heart of Silicon Valley like you seem to be implying).

This results in things like GnuPG being considered hard to use. This results in things like GnuPG struggling along with a single core developer and barely enough funding to support that developer (even now). This results in things like OpenSSL being horribly undermaintained, to the point where nasty bugs like Heartbleed are allowed to exist longer than they should because there is an insufficient quantity of eyeballs to find them and squish them. It doesn't take a rocket surgeon or a cryptographic guru to see that this is nothing but an awful situation for pretty much everyone involved.

Re: GPG and Me

#259

Earlier quoted context omitted.

Yes, there is a reason to discourage those people. In between the time that a cryptographically illiterate developer releases their MVP 1.0 version and the time that it's discovered that their cryptography is fundamentally flawed --- a window of time that can stretch on for years --- actual people will rely on the tool for their security, not realizing that serious adversaries are reading their messages. Most new cry…

My point is that this attitude of "only people who have proven themselves as cryptography geniuses may dare to think about thinking about cryptographic protocols" also discourages the potential UX/UI/workflow/etc. programmers from participating, since it gives the impression that their contributions will never be "good enough" to be accepted. It also discourages potential developers of the crypto algorithms and proto…

[deleted]

Re: GPG and Me

#260

I am curious as to to know what mail clients people are using with GPG. In OSX I am not a big fan of the native mail client at all but it seems thats the only approach if you want to use GPG. I am currently on a quest to find a decent mail client that looks good and works well and I am currently trialling Airmail 2 but its GPG support is buggy at best.

I use Thunderbird with Enigmail, but for some reason it wants to load up thousands of archived emails and crashes my computer. It is annoying as fuck.

While I really enjoy reading and sending encrypted emails, and think it's far better than sending sensitive data in the clear, I am surprised to learn that there are people who use PGP and don't hate it or have issues with it.

Post reply on HN