Live data from Hacker News

Facebook and PGP

cs.columbia.edu

11–20 of 60 posts

Re: Facebook and PGP

#11
post #2

Another possibility is one of their programmers thought "It would be good if there was more encrypted e-mail going around in general, I wonder if I can get it into facebook somehow" and coded this feature in their free time. Then convinced his managers to integrate it with that argument plus "and it's already coded we just need to merge it in"

Well, from what I know there are some seriously privacy minded people in there. As oxymoronic as that sounds.

But I could certainly see some benefits both for FB and for world at large from this. One of the big problems with PGP is how to bootstrap web of trust. "Does this key really belong to this particular person?" But what if the otherwise loathed real name policy could be turned to service this particular need? Prominently visible personalities can attach their PGP keys to their pages and make the first association harder to forge.

Secondly, I have little doubt that the keyservers are monitored. An increase of searches and/or downloads to known activist lawyers' or journalists' keys could have relation to uncomfortable whistles being blown in near future. But what if FB made the keys they have signed available via their own keyserver, and made that reachable over Tor? Downloading a high-profile PGP key is likely to be a fairly big red flag.

And lastly, there may be some positive effects further down the line. I've been using PGP (and later GPG) since 2.3i became available and I know just how horrid the usability is. If FB can iterate over UI and UX issues, then others can learn from those efforts, and eventually we might have something that even a regular person could at least learn to use.

And of course - adding more encrypted noise to global email flow is not a bad thing at all.

I have no doubt that FB sees many non-altruistic avenues if this service catches wind. Wonder is there is anything to relationship graphs with some extremely strong edges...

Re: Facebook and PGP

#12
post #7

The last paragraph of the linked post describes more or less what keybase [1] is. [1] https://keybase.io/

A little of topic, but if someone would like a invite to keybase let me know :-)

From their CEO[1]:

Heck. In honor of FB's move, Keybase signups are open for the next 24h. Please one account per person. Use invite code: shit-yeah-facebook

[1] https://twitter.com/malgorithms/status/605807605659758592

Re: Facebook and PGP

#13

Btw, does PGP support triple wrapping to prevent surreptitious forwarding? (S/MIME does - https://www.ietf.org/rfc/rfc2634.txt ) I really don't understand why it has been chosen over S/MIME. Maybe they gave the money to that german guy who wrote it and now they don't want them to be completely wasted :)

Despite his German sounding name, I can assure you that Phil Zimmermann, the creator of PGP, is very much an American.

Re: Facebook and PGP

#15
post #2

Another possibility is one of their programmers thought "It would be good if there was more encrypted e-mail going around in general, I wonder if I can get it into facebook somehow" and coded this feature in their free time. Then convinced his managers to integrate it with that argument plus "and it's already coded we just need to merge it in"

"and it's already coded we just need to merge it in"

Any manager worth their salt will know that maintaining code is 10x more expensive than building it in the first place, and if it's user-facing code you're even adding an implicit promise that the feature isn't going to be removed again. I strongly doubt the "oh but it would be so hard to build that" argument counts for much.

That said, I've no idea about what kind of place Facebook really is.

Re: Facebook and PGP

#16

Btw, does PGP support triple wrapping to prevent surreptitious forwarding? (S/MIME does - https://www.ietf.org/rfc/rfc2634.txt ) I really don't understand why it has been chosen over S/MIME. Maybe they gave the money to that german guy who wrote it and now they don't want them to be completely wasted :)

Despite his German sounding name, I can assure you that Phil Zimmermann, the creator of PGP, is very much an American.

I think he meant GPG. http://en.m.wikipedia.org/wiki/Werner_Koch

Re: Facebook and PGP

#18

Back in the Myspace era, I was bored and created an easy encoder-decoder for people to play with. It worked with Twitter, Facebook and Myspace (cut-paste your encoded text) because it only used basic characters. As you can't see in this animation, I later added random spaces and punctuation to the encoded text so that theoretically it would be harder for social networks to detect and block. The text was encoded in Ja…

I don't think anyone cares or should care about easy-to-break encryption. Encoding and decoding your messages has a cost, there needs to be a benefit beyond "looking cool".

Re: Facebook and PGP

#19

Btw, does PGP support triple wrapping to prevent surreptitious forwarding? (S/MIME does - https://www.ietf.org/rfc/rfc2634.txt ) I really don't understand why it has been chosen over S/MIME. Maybe they gave the money to that german guy who wrote it and now they don't want them to be completely wasted :)

Despite his German sounding name, I can assure you that Phil Zimmermann, the creator of PGP, is very much an American.

He meant Werner Koch, the guy who is maintaining gnupg A few months ago, he asked again for donation, this time he got "good media exposure" and got funded. cf https://news.ycombinator.com/item?id=9011138

Facebook pledged to donate $50,000 a year to Koch’s project.

Re: Facebook and PGP

#20

Btw, does PGP support triple wrapping to prevent surreptitious forwarding? (S/MIME does - https://www.ietf.org/rfc/rfc2634.txt ) I really don't understand why it has been chosen over S/MIME. Maybe they gave the money to that german guy who wrote it and now they don't want them to be completely wasted :)

S/MIME has very little adoption - the kind of people who care about encrypting their email are usually the same kind of people who don't trust the CA system.
Post reply on HN