Live data from Hacker News

Facebook Is Ending Support for PGP Encrypted Emails

joltmailer.com

21–30 of 69 posts

Re: Facebook Is Ending Support for PGP Encrypted Emails

#21
post #4

After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…

> I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. If it was, they did us all a favour, because PGP as means of encrypting emails is a steaming pile of garbage, as it requires both, client support, and the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else) Email was never meant t…

HTML support client side, and required libraries are crazy complex compared to gpg integration. Yet that was done, and never meant to be.

Same for images inline, and the idea of attachments was an add-on. Other examples abound.

While I don't use html in my emails, it's effectively a standard now. So much so, that I have to prod some corporations to fix their stuff.

My point is, the "email was never meant" ship sailed decades ago. Change happens.

And there is no way to encrypt anything, ever, and send it to someone, who can't see it, and then copy it and send to others. A person can take a screen shot, or just take a phone and take a pic of the screen! So even if it's not simple, this problem is a non-solve, because if a human can read it, it can be copied to others.

Which means, I do not believe your criticism on this point is valid.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#22

> Once a hacker gains access to a Facebook account, they can proceed to activate email encryption. > This renders recovery emails sent to the user’s email address unreadable, as only the hacker has the encryption keys. So: PGP encrypted emails were rarely used, except to lock out the legit user after account was compromised.

Almost sounds like a feature. :-)

Re: Facebook Is Ending Support for PGP Encrypted Emails

#23

I doubt that this was widely adopted Hell, even amongst my peers, I'm continually shocked at how many people have never used gpg, ever. And, anecdotally, the number gets lower as age gets lower. Young people aren't using it. It's dying.

Makes sense to me, it was never super usable. The Windows versions in the early 2000s were ok enough (PGPWin by Symantec?) but outside of that, it was by CLI lovers for CLI lovers which is fine but this could only have worked with massive adoption driving network effects. Not to even mention keysigning parties, that were just the nerdiest thing ever :)

Re: Facebook Is Ending Support for PGP Encrypted Emails

#24

I doubt that this was widely adopted Hell, even amongst my peers, I'm continually shocked at how many people have never used gpg, ever. And, anecdotally, the number gets lower as age gets lower. Young people aren't using it. It's dying.

GPG sadly never grew up. It's a program firmly stuck in the 90s.

The original PGP manual talked about secretly communicating with your lover. That was the usage model, transmitting secret messages to people you could sometimes meet in person, and where the model was you talking to people you directly know.

Try to verify the GPG signature on say, the Tor Browser. It's signed by "Tor Browser Developers (signing key)". Have you ever met this "Tor Browser Developers" person?

Okay, what about the web of trust? Well, GPG offers no help whatsoever in finding a way of making a connection.

And that's why it's dying, because the model it targets ceased to be relevant, and we developed plenty new needs like verifying software signed by random people on the other side of the globe, while GPG did nothing to accommodate that use.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#25
post #4

After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…

> I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. If it was, they did us all a favour, because PGP as means of encrypting emails is a steaming pile of garbage, as it requires both, client support, and the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else) Email was never meant t…

The state actors did us a favor by making the most widely used email encryption scheme less useful?

I must assume you are an opponent of privacy

Re: Facebook Is Ending Support for PGP Encrypted Emails

#26

I doubt that this was widely adopted Hell, even amongst my peers, I'm continually shocked at how many people have never used gpg, ever. And, anecdotally, the number gets lower as age gets lower. Young people aren't using it. It's dying.

It's not dying. It's a secret thing, why would anyone advertise whether they use pgp or not...

Re: Facebook Is Ending Support for PGP Encrypted Emails

#27
post #4

After persons destroyed the usefulness and value of all the keyservers a few years back, via flooding and other actions, this is no shock. I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. Many people I know were starting to use it, now they do not. It doesn't matter that security should overcome conveniences, conveniences often win. An…

That only means it failed in its aim, and needs to be replaced with something better. If you really rely on encryption for something important, a system so easily broken is no good.

And "state actor funded"? Come on, the spam attack was absolutely trivial. It required no state funding, just a single person with an axe to grind, a target, and a trivial shell script. Attaching spam signatures was a thing decades ago already and didn't require any real resources of technical knowledge.

Post reply on HN