Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

191–195 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#191
post #105

Earlier quoted context omitted.

I'm not talking about deploying/using PGP to be secure from gov't (or Gmail) monitoring. I'm talking its use in the context of 99% of normal interactions online. Yes, we wouldn't have tinfoil-hat-level security if it was managed by Gmail, Yahoo, etc. But we'd be lightyears further ahead in our ability to interact securely with others online.

Okay, I'll bite for that - what's your threat scenario here?

These aren't threat scenarios. They're advantages to having PGP

Eliminate most spam. Talk with your bank/do trades over email. Talk with your physician. Sign documents.

With webmail-based PGP, people are strongly incentivized to use this to avoid requiring users to sign in to other websites.

Re: Encrypt your Google chats and make the NSA sad

#192
post #101

Earlier quoted context omitted.

I'm talking about the non-extreme-security case of where the online email provider stores your private keys.

So, in practical terms, how would this be more secure than what we have now? The main crux of PRISM is that they have highly automated mechanisms of accessing user data from many major internet companies. If you store your private keys alongside that, what are you trying to protect against?

The point isn't to hide data from the NSA. The point is that widely-used PGP would be really useful for all kinds of reasons, but that we don't have it because it would be inconvenient for the NSA if we did (they wouldn't be able to read the world's email, e.g.).

In practical terms, it would mean we could talk with physicians, brokers, banks. We could sign documents. We could get rid of nearly all spam. I mean, the advantages of widely deployed PKI are MASSIVE. And the quickest way to get there is to have webmail providers deploy it.

Re: Encrypt your Google chats and make the NSA sad

#193
post #135

Earlier quoted context omitted.

Here's Glenn either being intellectually dishonest or intellectually incompetent. http://www.samharris.org/blog/item/dear-fellow-liberal2

When I read that I see Sam Harris attributing things like "honor killings" to the doctrine of Islam as if Islam is a monolithic entity. He's equating the extremists with the mainstream and that is exactly what the islamaphobes do - insist that the crazies are the ones who have the true interpretation of islam and that the vast majority of regular muslims don't count because they aren't crazy. It is kind of like sayin…

I think it's fair to say "religion X causes honor killings" if and only if X's teachings encourage them (by explicitly saying there's no spiritual punishment for them, for example). It's also fair to say that "religion X doesn't cause honor killings" if there's no correlation between religion X and honor killings. I agree that correlation on its own is never enough.

So: do the teachings of those with a mantle of religion-X authority, on average, encourage or discourage honor killings? This is not a question we should avoid asking just because we want to be nice.

I don't see any evidence that Sam Harris has got this wrong.

Good point about being nice vs. reaching a permanent accommodation.

Re: Encrypt your Google chats and make the NSA sad

#194
post #191

Earlier quoted context omitted.

Okay, I'll bite for that - what's your threat scenario here?

These aren't threat scenarios. They're advantages to having PGP Eliminate most spam. Talk with your bank/do trades over email. Talk with your physician. Sign documents. With webmail-based PGP, people are strongly incentivized to use this to avoid requiring users to sign in to other websites.

I don't think having to sign into other websites is that much of a bother, nor that people are that motivated to talk to their bank or physician on a regular basis that would drive adoption of this sort of thing.

And in return you have to stick all your eggs in one basket, get what would probably end up being a single persistent online identity that goes under your real name (if it's tied to an email address you use for business stuff), and that's owned by a company and may not even be willing to give them back to you (would you even own the private keys if it was being implemented on the server?)

Re: Encrypt your Google chats and make the NSA sad

#195
post #191

Earlier quoted context omitted.

These aren't threat scenarios. They're advantages to having PGP Eliminate most spam. Talk with your bank/do trades over email. Talk with your physician. Sign documents. With webmail-based PGP, people are strongly incentivized to use this to avoid requiring users to sign in to other websites.

I don't think having to sign into other websites is that much of a bother, nor that people are that motivated to talk to their bank or physician on a regular basis that would drive adoption of this sort of thing. And in return you have to stick all your eggs in one basket, get what would probably end up being a single persistent online identity that goes under your real name (if it's tied to an email address you use…

There's really an amazing lack of imagination here, both from a threat avoidance perspective and a potential awesomeness one.

The deployment model is this: one large webmail provider starts doing PGP by default via its webclient. Maybe it provides your with private keys, maybe it doesn't. Fact is that it doesn't much matter, because as soon as a large webmail provider starts doing PGP/PKI, the two biggest problems with adoption (namely, that there's no one to use it with, and it's kind of a pain to use anyhow) are basically solved. And as soon as this happens, there starts being a competitive market where providers can begin improving on each other's implementations. Any provider that doesn't give users their private keys won't have much of an ethical argument for doing so, and so it probably would, anyway. There will, as always happens, be a feature war, except with PGP involved some of that war will involve privacy/encryption/reliability concerns.

(PGP also makes spear phishing much harder).

Post reply on HN