Live data from Hacker News

Facebook Is Ending Support for PGP Encrypted Emails

joltmailer.com

1–10 of 69 posts

Re: Facebook Is Ending Support for PGP Encrypted Emails

#3
> Once a hacker gains access to a Facebook account, they can proceed to activate email encryption.

> This renders recovery emails sent to the user’s email address unreadable, as only the hacker has the encryption keys.

So: PGP encrypted emails were rarely used, except to lock out the legit user after account was compromised.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#4
After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock.

I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG.

Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win.

And state actors hate encryption at rest.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#5
post #4

After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…

It's that, and the fact that a hacker would enable the feature after compromising the account (some other way, unrelated to PGP) to prevent the legit user from using the account recovery email.

So feature was basically there only to shoot oneself in the foot.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#7
post #4

After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…

It's that, and the fact that a hacker would enable the feature after compromising the account (some other way, unrelated to PGP) to prevent the legit user from using the account recovery email. So feature was basically there only to shoot oneself in the foot.

That is part of facebook's reasoning, as to why they dropped it. The second part should be kept in mind, and that is, few use it.

If it was popular, they wouldn't axe it.

My comment was certainly about facebook dropping it, but also about how this is a larger picture issue. You don't need to weaken encryption standards(NSA, others), or have back doors(loads of states), if people just find it too annoying to use!

Re: Facebook Is Ending Support for PGP Encrypted Emails

#8

I don't understand how the attack works. Does the workflow for enabling, or changing, Facebook email PGP keys not include an email verification step? Or is that being circumvented in some way?

It's just a DoS attack. If valid PGP pubkey is added to account, the account recovery email becomes useless because it's encrypted gibberish that cannot be deciphered unless you have PGP private key.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#10

I don't understand how the attack works. Does the workflow for enabling, or changing, Facebook email PGP keys not include an email verification step? Or is that being circumvented in some way?

It's just a DoS attack. If valid PGP pubkey is added to account, the account recovery email becomes useless because it's encrypted gibberish that cannot be deciphered unless you have PGP private key.

Can you associate a PGP pubkey to an email address, in Facebook's workflow, without verifying access to that address?
Post reply on HN