Live data from Hacker News

OpenPGPjs v3.0

protonmail.com

21–30 of 46 posts

Re: OpenPGPjs v3.0

#21

I wish something like this would take off - https://github.com/kylehuff/webpg-chrome We deserve a better userspace from our browsers. The excuse that "users" don't want this because its "hard" is circular.

The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(

What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...

Re: OpenPGPjs v3.0

#22
post #17

What is the threat model for PGP in JS? Like, is there an Alice, Bob, Carol, Eve story under which PGP in JS makes sense? The canonical example that IMO doesn't make sense is when Alice and Bob want to communicate privately using Eve as an webmail provider who wants to snoop in on the communications. Alice and Bob can't just trust Eve to provide a copy of OpenPGPjs in a tag on EveMail.com, because then they're trusti…

I've been looking for gmail alternatives and this is my conclusion. Protonmail plays the part of the secure and private email provider, but, technologically, can't provide that. The only concrete thing their users have going is the superior legal environment of Switzerland. A less-than-concrete comforter is that if we believe that the people behind Protonmail believe in privacy, we'll tend to think they're more likel…

So, that's a conclusion but no reasoning behind it, therefore it's impossible to evaluate critically.

Re: OpenPGPjs v3.0

#23
post #7

Earlier quoted context omitted.

> In case anyone that doesn't follow the development of the library closely missed it, the main improvement in this version is the introduction of ECC support. Wow...I'm sort of shocked that wasn't a v1.0 consideration. > ECC tends to be able to provide equivalent levels of security as traditional "big prime" cryptography (like RSA) with less computationally intensive operations. This is especially important in a lib…

Aren't there multiple operating quantum computers right now? Isn't this a very imminent problem?

Depends what qualifies as a quantum computer. It is questionable whether current 'quantum computers' deserve the name.

Re: OpenPGPjs v3.0

#24

Earlier quoted context omitted.

The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(

What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...

I got a certificate error as well. This site hasn't had its certification for 132 days. I thought the whole link was a super meta joke/test. It does look cool though. Thanks for posting.

Re: OpenPGPjs v3.0

#25

Earlier quoted context omitted.

The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(

What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...

I'm also getting it. The certificate for https://webpg.org/ expired October 29, 2017.

Re: OpenPGPjs v3.0

#26

Earlier quoted context omitted.

The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(

What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...

[deleted]

Re: OpenPGPjs v3.0

#27
post #7

Earlier quoted context omitted.

> In case anyone that doesn't follow the development of the library closely missed it, the main improvement in this version is the introduction of ECC support. Wow...I'm sort of shocked that wasn't a v1.0 consideration. > ECC tends to be able to provide equivalent levels of security as traditional "big prime" cryptography (like RSA) with less computationally intensive operations. This is especially important in a lib…

Aren't there multiple operating quantum computers right now? Isn't this a very imminent problem?

Yes and no. To simplify matters, you need not just a quantum computer but such a machine with the right sort of qubits. The right sort of qubits being logical qubits, not physical, many of which are needed for error correction.

It's not clear whether we can currently create a machine with sufficient logical qubits to run Shor's algorithm in a meaningful way.

However, out of an abundance of caution, we're "starting" now (some designs have existed for longer but this (NIST PQC) is the first competition, which focuses minds) so as to have something ready when/if a quantum computer becomes a reality.

Re: OpenPGPjs v3.0

#28

I wish something like this would take off - https://github.com/kylehuff/webpg-chrome We deserve a better userspace from our browsers. The excuse that "users" don't want this because its "hard" is circular.

The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(

Expired certificate is probably the least egregious security error, especially for a homepage.

No data is lost or stolen. Customers won't like it, you may lose sales, etc, but your data security is fine.

Re: OpenPGPjs v3.0

#29
post #25

Earlier quoted context omitted.

What certificate error? Neither https://openpgpjs.org nor the link here have a certificate error for me. Maybe you are being MITMed...

I'm also getting it. The certificate for https://webpg.org/ expired October 29, 2017.

Aha, I misunderstood the original comment.

Re: OpenPGPjs v3.0

#30

Earlier quoted context omitted.

The project looks really cool! But...the fact that the website has a certificate error doesn't inspire much confidence. Especially since it's a security tool. :(

Expired certificate is probably the least egregious security error, especially for a homepage. No data is lost or stolen. Customers won't like it, you may lose sales, etc, but your data security is fine.

It's a sign of either laziness, incompetence, or lost interest, and none of those things are good.
Post reply on HN