Earlier quoted context omitted.
Yes. That they have a large impact does not change the fact that not I nor anyone in my close circle uses it for that. It has been relegated to a specialized domain and use case. I have no use for maintaining a signing key. All the communications I need to secure and verify identity use a different technology for it. The fact that some tools I run might use it in the background is entirely abstracted away for me and…
If you write open source code others rely on, or have any online identity that could be used for harm if stolen, it is irresponsible to not have a well published public identity signing key that cryptographically ties together your online presences to make you hard to impersonate. A key used to sign commits, binaries, code reviews, emails, or anything else of public value you produce. If you do not do anything of con…
Switching from GPG to Age
121–130 of 148 posts
Re: Switching from GPG to Age
#122Earlier quoted context omitted.
You spend a lot of energy steering people away from PGP, but what is your alternative to solve the same problems with the same threat models? What do you want to shift the entire software supply chain security foundation of the internet to use instead and how? Complaining the existing solution is not good enough is easy. Making things better and educating on current best efforts without creating centralized points of…
Did you not read the post I linked upthread? You were quite confident in refuting its claims, so I assume we shared an understanding here. Update It looks like you drastically edited your comment after I replied to it, in ways that change the meaning of your prompt. That makes it impossible for us to continue discussing anything.
Re: Switching from GPG to Age
#123Earlier quoted context omitted.
> In what situations do you want people to discover your key Just to name some of the most common use cases I have: 1. When people in my orgs want to encrypt sensitive information to me, e.g in encrypted password databases over git. 2. When prospective new clients or security researchers want to encrypt sensitive requests to me via email. Have some in my inbox right now from today. 3. When people want to verify that…
> A PGP key is the only standardized cryptographic passport for the internet I think this rather gives the game away. For people for whom PGP is important, their PGP key is their identity. And there is a community of people like this. But it's small--I'd guesstimate maybe a million people or so at best, a true rounding error in terms of the internet. For most people, however, their online identity is generally tied a…
But to your point, not nearly enough people have a concept of a desire to want digital sovereignty. Ownership of their own identity in a way a company has no control of.
And the ones curious about this concept, find the barrier to explore it impossibly high. That is why I have been so convinced in recent years that UX and social dynamics matter in cryptography as much as the math behind it.
That is why we put so much thought into keyfork. We realized it has to be one or two commands tops to be up and running with a new keychain or no one is going to do it.
Re: Switching from GPG to Age
#124Earlier quoted context omitted.
If you write open source code others rely on, or have any online identity that could be used for harm if stolen, it is irresponsible to not have a well published public identity signing key that cryptographically ties together your online presences to make you hard to impersonate. A key used to sign commits, binaries, code reviews, emails, or anything else of public value you produce. If you do not do anything of con…
Except that I do all of those things and I don't care about it at all nor does the absence affect me in any way. Keybase was a nifty chat.
Re: Switching from GPG to Age
#125Earlier quoted context omitted.
In my experience building bug bounty programs for many high risk orgs, PGP reports are rare, as you indicate. Maybe a couple a year. That does not make them any less critical or relied on. We always took them super seriously and read them offline because they were often highly sensitive real disclosures that merited being exposed only to a very small circle of people with security team decryption smartcards. It is a…
You haven't responded to my point. I would happily run a bounty program without a PGP key; in fact, I'd recommend not publishing a PGP key, and instead making arrangements to communicate a Signal identity.
I also may want to do this anonymously.
Signal is the wrong tool on both counts. Fine to have as an option but I would never have that as the only option.
Re: Switching from GPG to Age
#126Earlier quoted context omitted.
You haven't responded to my point. I would happily run a bounty program without a PGP key; in fact, I'd recommend not publishing a PGP key, and instead making arrangements to communicate a Signal identity.
If I as a security researcher want to send a super sensitive disclosure to an organization like "I have reason to believe your devices are compromised", I want to be damn sure it goes to a PGP key held on smartcards that decrypt reports on airgapped operating systems. I also may want to do this anonymously. Signal is the wrong tool on both counts. Fine to have as an option but I would never have that as the only opti…
More of them required password-protected ZIPs than PGP, so much so that we had a whole complicated document to ensure we were using the versions of ZIP file programs that used AES and not Bass-o-matic.
Apple and Google routinely get findings worth 6-7 figures that aren't PGP encrypted.
PGP-encrypting bug bounty submitters are mostly LARPing.
I will take the Pepsi Challenge with you on experience with bounty programs if you'd like. But here's another question: have you ever been on a major-vendor embargo list before? Was it your experience that those embargo lists were uniformly PGP-encrypted? (I can spoil this one for you if you like).
Tell me more about how major vulnerability disclosures depend on PGP, please.
Re: Switching from GPG to Age
#127Earlier quoted context omitted.
If I as a security researcher want to send a super sensitive disclosure to an organization like "I have reason to believe your devices are compromised", I want to be damn sure it goes to a PGP key held on smartcards that decrypt reports on airgapped operating systems. I also may want to do this anonymously. Signal is the wrong tool on both counts. Fine to have as an option but I would never have that as the only opti…
That is very silly. I founded and ran what was at the time the 2nd or 3rd largest software security consultancies in North America, then acquired and rolled up into what was the largest software security consultancy in North America (NCC Group US), our client list was a phone book of every major tech firm and every major manufacturer and infrastructure company with a significant code footprint, our firm at its peak w…
This just seems to be an appeal to authority. I will just say your credentials do not impress me.
Lets just stick to two security engineers on different sides of the same industry having a technical merits discussion.
In any event I did not once claim PGP encrypted reports are common, but I can say of the dozens I have received, most were very high quality from actual security researchers, and some have made me very happy I insisted such reports be decrypted offline on a machine I absolutely trust.
It is good to give people options, and especially at least one that can be used anonymously with a fully open source operating system using a decentralized very widely used and established standard.
I for one have made more than a few very sensitive security reports and do not own a Google or Apple controlled device or a Signal account.
Re: Switching from GPG to Age
#128Earlier quoted context omitted.
That is very silly. I founded and ran what was at the time the 2nd or 3rd largest software security consultancies in North America, then acquired and rolled up into what was the largest software security consultancy in North America (NCC Group US), our client list was a phone book of every major tech firm and every major manufacturer and infrastructure company with a significant code footprint, our firm at its peak w…
> That is very silly. I founded and ran what was at the time... This just seems to be an appeal to authority. I will just say your credentials do not impress me. Lets just stick to two security engineers on different sides of the same industry having a technical merits discussion. In any event I did not once claim PGP encrypted reports are common, but I can say of the dozens I have received, most were very high quali…
Re: Switching from GPG to Age
#129Earlier quoted context omitted.
I would appreciate it if you answered to the rest of my comment. It may be quite useful.
I will not, because I joined this subthread to make a specific point (that the other commenter was simply wrong that the archaisms in PGP/OpenPGP are a mere consequence of GnuPG and avoidable by avoiding GnuPG), and this whole subthread has been an exercise in avoiding that point and switching to other more tractable arguments. I'm sorry, but I'm not interested.
> (that the other commenter was simply wrong that the archaisms in PGP/OpenPGP are a mere consequence of GnuPG and avoidable by avoiding GnuPG)
Didn't read it like that though, it read like "OpenPGP is shit", and I could quote you where you are claiming exactly that:
> outmoded fundamentally, not just by one implementation
You said this, about OpenPGP.
Welp.
Re: Switching from GPG to Age
#130Earlier quoted context omitted.
Minisign and Age entirely dodge the actually hardest problem with humans using cryptography, that PGP puts front and center: identity and public key discovery. You cannot just skip these! If a human focused cryptography tool gives a user no way to know if they are encrypting to the correct public key of someone else, or no way to distinguish a real signature from one of an impersonator, then the tools failed to do th…
PGP does an absolutely dreadful job of key discovery, and further, there is no reason to couple one mode of "key discovery" to a signing tool. Different business domains will have different optimal key discovery architectures. My guess is that at this point more professional environments (think on the level of "companies and projects") have integrated age and minisign than have integrated PGP, which is striking given…
I know of no solutions even close to this for Minisign or Age keys that does not rely on centralized corporations like Microsoft.