Live data from Hacker News

Facebook Is Ending Support for PGP Encrypted Emails

joltmailer.com

11–20 of 69 posts

Re: Facebook Is Ending Support for PGP Encrypted Emails

#11

I don't understand how the attack works. Does the workflow for enabling, or changing, Facebook email PGP keys not include an email verification step? Or is that being circumvented in some way?

It's just a DoS attack. If valid PGP pubkey is added to account, the account recovery email becomes useless because it's encrypted gibberish that cannot be deciphered unless you have PGP private key.

A new key can (should) be activated only if a user can confirm that they can read messages encrypted with this key sent to a configured account recovery email.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#12
post #7

Earlier quoted context omitted.

It's that, and the fact that a hacker would enable the feature after compromising the account (some other way, unrelated to PGP) to prevent the legit user from using the account recovery email. So feature was basically there only to shoot oneself in the foot.

That is part of facebook's reasoning, as to why they dropped it. The second part should be kept in mind, and that is, few use it. If it was popular, they wouldn't axe it. My comment was certainly about facebook dropping it, but also about how this is a larger picture issue. You don't need to weaken encryption standards(NSA, others), or have back doors(loads of states), if people just find it too annoying to use!

Would have helped a lot of there would have been some sponsorship and adoption by banks, bigtech, governments. With only push from Snowden and a couple of nerds (I'm making a hyperbole :-) ) and it being complicated, inconvenient this never gained momentum.

Banks, bigtech, government choose other means, for their own reasons. Some of those might have been spies lobbying to hold on to their surveillance superpowers, for sure. Another might have been "not invented here".

Re: Facebook Is Ending Support for PGP Encrypted Emails

#13

Earlier quoted context omitted.

It's just a DoS attack. If valid PGP pubkey is added to account, the account recovery email becomes useless because it's encrypted gibberish that cannot be deciphered unless you have PGP private key.

Can you associate a PGP pubkey to an email address, in Facebook's workflow, without verifying access to that address?

Not sure, I don't use Facebook. I suppose that if you have access to the account and are able to associate PGP, you might as well change the recovery email address too if hacker doesn't already have a way to read it.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#14

Feels like killing a feature for the sake of an edge-case. What's the prevalence of malignant entities taking over a Facebook account (of all accounts you can nick) via PGP takeover?

Facebook account takeovers are really elaborate and very common. Since this is a very easy way to essentially block users from recovering their own account, I can see why they're killing this vector. The account was not taken over through the feature, but the feature made self-service recovery near impossible.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#15
post #4

After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…

> I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG.

If it was, they did us all a favour, because PGP as means of encrypting emails is a steaming pile of garbage, as it requires both, client support, and the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else)

Email was never meant to be encrypted, and the existing implementations (including S/MIME) suck for this exact reason. And the worst thing is that it’s simply not possible to make it work.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#17

I don't understand how the attack works. Does the workflow for enabling, or changing, Facebook email PGP keys not include an email verification step? Or is that being circumvented in some way?

Even email verification might not be enough. Consider the following scenario

1. Attacker somehow gets control of email

2. Attacker uses email to "recover" facebook.

3. Attacker uses email to add pgp.

(time passes)

4. User realizes facebook and email are taken over

5. User somehow recovers email

6. User tries to recover facebook using email but is unable to

Re: Facebook Is Ending Support for PGP Encrypted Emails

#18

> Once a hacker gains access to a Facebook account, they can proceed to activate email encryption. > This renders recovery emails sent to the user’s email address unreadable, as only the hacker has the encryption keys. So: PGP encrypted emails were rarely used, except to lock out the legit user after account was compromised.

Github asks you to log in again to add SSH keys in, this could've been similar

They're just looking for excuses

Re: Facebook Is Ending Support for PGP Encrypted Emails

#19
post #2

Presumably the is no overlap in the Venn diagram of people who want PGP encrypted emails and people who use Facebook,

Once upon a time I tried to adapt Mailvelope to encrypt FB messages, for what it's worth. But that was a long, long, LONG time ago.

https://mailvelope.com/en/

Re: Facebook Is Ending Support for PGP Encrypted Emails

#20
post #4

After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…

> I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. If it was, they did us all a favour, because PGP as means of encrypting emails is a steaming pile of garbage, as it requires both, client support, and the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else) Email was never meant t…

> PGP as means of encrypting emails is a steaming pile of garbage, as it requires [...] the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else)

All encrypted communication protocols have this requirement. And all of them will in the future. By definition, you need the counterparty to be able to decrypt your message, which means you're always vulnerable to them forwarding the unencrypted message to anyone they want.

Post reply on HN