Live data from Hacker News

GPG and Me

thoughtcrime.org

191–200 of 267 posts

Re: GPG and Me

#191
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

Why 50k users? PGP/GnuPG is used to secure a _lot_ more than email.

Every Linux distribution signs packages with it. So that's at least 100M users right there. Several APIs regarding domain name and AS registrations is based on it. I know at least two financial systems that signs their messages with it. That's just mentioning a few I can think of right now. I'm sure it secures a lot lot more. It's used all over the place and it seems to do the job fairly well in most cases.

Is it suitable for signing email in 2015? I don't know. Things could certainly be improved. I know there are more suitable schemes for IM communciation. But the software and the underlying protocol is not something you can break in a heartbeat. It's important software.

Perhaps we need to speak more of the evolving use case in email?

Re: GPG and Me

#192
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

One of the biggest problems with GPG is keyex. Sure, we have key servers, but that's not really a secure way of doing things. Secure communication is as much a cultural change as a technological one.

GPG at least has the web of trust, with all its privacy problems. Most technologies just use "trust on first use".

Re: GPG and Me

#193
post #55

I don't want GPG to get in the way of better, newer options. But even less do I want to read more about people burned by the incompetent engineering of lesser new alternatives. Can we just declare a flag day and switch to TextSecure?

Yes, but not unless: 1. there are full-featured native clients for computers that aren't smartphones 2. it works with anonymous accounts, without needing a phone number 3. federation is open Right now, TextSecure can't even fully replace OTR (for secure IMs), let alone GPG (for email <- real work).

To replace email, we might want named conversations as well.

Re: GPG and Me

#194
post #176

Sorry but what is the actual point of this blog post? GPG is just one guy. Who's practically beggared himself writing and maintaining the tool. GPG is actually used by human rights activists, journalists etc. That, right there, is reason enough to celebrate it and NOT "kill it off". I think the massive pile-on this is creating is really dumb, to be honest. So Moxie thinks it could be done better; that's great. He's g…

> Why waste time denigrating a project that's basically a labour of love for one guy that is actually tremendously important, even if it's "90's technology"? Old doesn't necessarily mean bad.

In the world of crypto, where we've learned so much, yes old means bad. Almost always.

Why denigrate GPG? Unfortunately, because the message that it's not good isn't being widely heard.

How many NEW crypto projects are being created that start out by saying, "first we will use GPG"? I've seen lots. OK, you failed right there, right at the start. Don't do that.

How many crypto geeks STILL spout rubbish about how the PKI is totally busted and the web of trust is the future? Way too many. WoT is sort of like the year of desktop Linux by now. It's just a bad joke that too many people won't let go of.

The most serious and effective applied cryptographers I know about are all ignoring GPG and rolling new modern crypto protocols. I feel the same way as Moxie - if you build a product based on GPG then almost immediately you are less interesting than a project that's doing something new.

And FWIW I have the same sinking feeling when I get a GPG encrypted email. Sometimes I don't read it immediately, I put it off. Sometimes I have to put it off because I'm not near my laptop. And when I decrypt it, inevitably I discover that I could have guessed the contents of the mail from the subject line and identity of the sender. The encryption was largely pointless to begin with.

The future of encrypted messaging is not GPG. We need to collectively let it go.

Re: GPG and Me

#195
post #131

I'm sick of "opinionated software". IMO it's code for "adding more settings is hard". I'd prefer "sane defaults" as an operating mode, and maybe burying confusing settings behind a warning screen like about:config in Firefox. Software that thinks it knows my use case better than I do is wrong.

In crypto options are dangerous, so it makes a lot of sense to be opinionated.

Re: GPG and Me

#196
I think a major part of the solution is going to involve teaching people about public key cryptography in school. It isn't the sort of thing that anyone wants to bother to learn on their own. Without this essential understanding any attempt to get the general public to protect their privacy is doomed. Even if they somehow manage to go through the motions they are eventually going to do something to mess everything up if they don't know what they are doing.

Some tasks require understanding. This is one of those tasks.

Re: GPG and Me

#197
post #186

Earlier quoted context omitted.

Specific criticisms of GPG: > the working hypothesis for privacy enhancing technology was simple: we’d develop really flexible power tools for ourselves, and then teach everyone to be like us... Instead of developing opinionated software with a simple interface, GPG was written to be as powerful and flexible as possible. It’s up to the user whether the underlying cipher is SERPENT or IDEA or TwoFish I think it's self…

You list plenty of specific problems with GPG the UI and GPG the "API" (though frankly the fact that mailpile would write 1400 lines of python that wrap GPG rather than taking one of the independent library implementations of RFC4880 and bringing it up to production quality makes them part of the problem). But none of those specific problems are problems with OpenPGP the protocol.

Well, I was only quoting the article, but it sounds like he has a good point that the protocol doesn't support forward secrecy. I also tend to trust his judgment that it's too complicated, and/or the complication adds little value for "normal" users. I guess some of this can be isolated as an app/API problem rather than protocol, as you say.

Re: GPG and Me

#198
post #175

Clever Marketing gig for TextSecure which has been rumbled by the third commentator on that page: > Okay, since you want to play in the same league as OpenPGP: where can I find the RFC describing TextSecure? How many independent implementations of the TextSecure protocol currently exist?

There is Whatsapp, which is not compatible but uses the Axolotl protocol as well.

You can find the protocol on github.

Re: GPG and Me

#199
Well, that is certaily an understandable position. I am very happy that such a software exists in the open source community, as unpractical it might be.

The trouble, however, does not start with the lack of UI design, or other impracticalities - for me it starts with the platform I choose to run a PGP type of software on.

Would you trust your Iphone, Android, Microsoft/Linux/iOS/Lenovo/Dell/et cetera computer with "really sensitive, mission critical" data?

I don't.

"The paranoid will survive" is a good sentence to remember. So I better install that PGP-etc on a offline unit and decrypt encrypt my messages there.

Re: GPG and Me

#200

Earlier quoted context omitted.

It's snake oil -- entropy isn't "depleted" in any meaningful way; once your kernel PRNG has accumulated enough entropy that you'd be comfortable using it to generate a crypto key it is not going to cease being suitable for that just because you continue asking it for random numbers.

/dev/random is an entropy estimating entropy pool that means it will block when it estimates that you have "used up" all of the available entropy you can check how many bits of entropy your kernel thinks are available easily cat /proc/sys/kernel/random/entropy_avail edit: i should have mentioned that there is some reason to argue against this behaviour but that doesn't change the usefulness of haveged for existing sy…

Yes, but that's a reason not to use /dev/random, not a reason to install snake-oil products.

The random(4) manpage is unfortunately exceptionally misleading, and has sadly led to a small but non-zero numbers of products that try to use /dev/random rather than /dev/urandom.

Sadly, gpg --gen-key doesn't even give you this option - but that's (as noted above) another flaw in GPG.

Post reply on HN