I don't understand how the attack works. Does the workflow for enabling, or changing, Facebook email PGP keys not include an email verification step? Or is that being circumvented in some way?
It's just a DoS attack. If valid PGP pubkey is added to account, the account recovery email becomes useless because it's encrypted gibberish that cannot be deciphered unless you have PGP private key.
Facebook Is Ending Support for PGP Encrypted Emails
11–20 of 69 posts
Re: Facebook Is Ending Support for PGP Encrypted Emails
#12Earlier quoted context omitted.
It's that, and the fact that a hacker would enable the feature after compromising the account (some other way, unrelated to PGP) to prevent the legit user from using the account recovery email. So feature was basically there only to shoot oneself in the foot.
That is part of facebook's reasoning, as to why they dropped it. The second part should be kept in mind, and that is, few use it. If it was popular, they wouldn't axe it. My comment was certainly about facebook dropping it, but also about how this is a larger picture issue. You don't need to weaken encryption standards(NSA, others), or have back doors(loads of states), if people just find it too annoying to use!
Banks, bigtech, government choose other means, for their own reasons. Some of those might have been spies lobbying to hold on to their surveillance superpowers, for sure. Another might have been "not invented here".
Re: Facebook Is Ending Support for PGP Encrypted Emails
#13Earlier quoted context omitted.
It's just a DoS attack. If valid PGP pubkey is added to account, the account recovery email becomes useless because it's encrypted gibberish that cannot be deciphered unless you have PGP private key.
Can you associate a PGP pubkey to an email address, in Facebook's workflow, without verifying access to that address?
Re: Facebook Is Ending Support for PGP Encrypted Emails
#14Feels like killing a feature for the sake of an edge-case. What's the prevalence of malignant entities taking over a Facebook account (of all accounts you can nick) via PGP takeover?
Re: Facebook Is Ending Support for PGP Encrypted Emails
#15After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…
If it was, they did us all a favour, because PGP as means of encrypting emails is a steaming pile of garbage, as it requires both, client support, and the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else)
Email was never meant to be encrypted, and the existing implementations (including S/MIME) suck for this exact reason. And the worst thing is that it’s simply not possible to make it work.
Re: Facebook Is Ending Support for PGP Encrypted Emails
#16Hell, even amongst my peers, I'm continually shocked at how many people have never used gpg, ever. And, anecdotally, the number gets lower as age gets lower. Young people aren't using it. It's dying.
Re: Facebook Is Ending Support for PGP Encrypted Emails
#17I don't understand how the attack works. Does the workflow for enabling, or changing, Facebook email PGP keys not include an email verification step? Or is that being circumvented in some way?
1. Attacker somehow gets control of email
2. Attacker uses email to "recover" facebook.
3. Attacker uses email to add pgp.
(time passes)
4. User realizes facebook and email are taken over
5. User somehow recovers email
6. User tries to recover facebook using email but is unable to
Re: Facebook Is Ending Support for PGP Encrypted Emails
#18> Once a hacker gains access to a Facebook account, they can proceed to activate email encryption. > This renders recovery emails sent to the user’s email address unreadable, as only the hacker has the encryption keys. So: PGP encrypted emails were rarely used, except to lock out the legit user after account was compromised.
They're just looking for excuses
Re: Facebook Is Ending Support for PGP Encrypted Emails
#19Presumably the is no overlap in the Venn diagram of people who want PGP encrypted emails and people who use Facebook,
Re: Facebook Is Ending Support for PGP Encrypted Emails
#20After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…
> I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. If it was, they did us all a favour, because PGP as means of encrypting emails is a steaming pile of garbage, as it requires both, client support, and the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else) Email was never meant t…
All encrypted communication protocols have this requirement. And all of them will in the future. By definition, you need the counterparty to be able to decrypt your message, which means you're always vulnerable to them forwarding the unencrypted message to anyone they want.