Live data from Hacker News

Facebook and PGP

cs.columbia.edu

21–30 of 60 posts

Re: Facebook and PGP

#21
Has anyone got an encrypted email from facebook yet? I uploaded my key and ticked the box, but the last notification I got was still in the clear.

Re: Facebook and PGP

#22
post #18

Back in the Myspace era, I was bored and created an easy encoder-decoder for people to play with. It worked with Twitter, Facebook and Myspace (cut-paste your encoded text) because it only used basic characters. As you can't see in this animation, I later added random spaces and punctuation to the encoded text so that theoretically it would be harder for social networks to detect and block. The text was encoded in Ja…

I don't think anyone cares or should care about easy-to-break encryption. Encoding and decoding your messages has a cost, there needs to be a benefit beyond "looking cool".

I have to agree, but I was looking to limit the "cost" by making it easy and fun. I could see the demographics, most of them had time to kill. And with young people, you never know what will be cool, fashionable or viral. Easy-to-break is subjective too. Sibling, parent, teacher, advertiser, somebody looking over your shoulder? They couldn't break it. I think every generation has something like this, a Cracker Jack decoder ring, passing notes in class, some 1337 letter generator.

Re: Facebook and PGP

#23
post #21

Has anyone got an encrypted email from facebook yet? I uploaded my key and ticked the box, but the last notification I got was still in the clear.

Yeah, I immediately-ish got an encrypted email asking me to confirm that I really wanted my notifications encrypted, and after I clicked the link I started getting encrypted notifications. Maybe check your spam?

Re: Facebook and PGP

#25

To me the strangest thing about this announcement is that, while the PGP user base is small, I imagine its intersection with Facebook's is much, much smaller. PGP is used by people who are extremely concerned with privacy, which is practically the antithesis of Facebook.

I agree with the demographics, but I've never understood this connection. With Facebook, the intrusion of privacy happens completely out in the open and you can work with that. By now pretty much everyone concerned knows that they collect and potentially use everything they can. With email interception, on the other hand, that's something you don't have any control over without encryption. So in my mind, I can be a heavy user of Facebook and a heavy user of PGP without any contradiction.

Re: Facebook and PGP

#26
post #11
post #2

Another possibility is one of their programmers thought "It would be good if there was more encrypted e-mail going around in general, I wonder if I can get it into facebook somehow" and coded this feature in their free time. Then convinced his managers to integrate it with that argument plus "and it's already coded we just need to merge it in"

Well, from what I know there are some seriously privacy minded people in there. As oxymoronic as that sounds. But I could certainly see some benefits both for FB and for world at large from this. One of the big problems with PGP is how to bootstrap web of trust. "Does this key really belong to this particular person?" But what if the otherwise loathed real name policy could be turned to service this particular need?…

> But what if the otherwise loathed real name policy could > be turned to service this particular need?

The link between a real person and a Facebook account isn't secure - I could make an account with your name today without too much stress (no need to provide ID unless Facebook thinks your name isn't a real name).

Re: Facebook and PGP

#27
post #7

The last paragraph of the linked post describes more or less what keybase [1] is. [1] https://keybase.io/

A little of topic, but if someone would like a invite to keybase let me know :-)

For anyone late, I have 9 invites. My details are on keybase: https://keybase.io/lekevicius

Re: Facebook and PGP

#28
post #25

To me the strangest thing about this announcement is that, while the PGP user base is small, I imagine its intersection with Facebook's is much, much smaller. PGP is used by people who are extremely concerned with privacy, which is practically the antithesis of Facebook.

I agree with the demographics, but I've never understood this connection. With Facebook, the intrusion of privacy happens completely out in the open and you can work with that. By now pretty much everyone concerned knows that they collect and potentially use everything they can. With email interception, on the other hand, that's something you don't have any control over without encryption. So in my mind, I can be a h…

> With Facebook, the intrusion of privacy happens completely out in the open and you can work with that.

I'm not following. Once I hand over my data I have no real control over how they end up using it behind the scenes. Furthermore, even if I never sign up with Facebook or at some point delete my account thinking my data has been flushed, a "shadow profile" still exists that I have no control over. [1]

[1] http://motherboard.vice.com/blog/facebooks-shadow-profile-bu...

Re: Facebook and PGP

#30
post #20

Btw, does PGP support triple wrapping to prevent surreptitious forwarding? (S/MIME does - https://www.ietf.org/rfc/rfc2634.txt ) I really don't understand why it has been chosen over S/MIME. Maybe they gave the money to that german guy who wrote it and now they don't want them to be completely wasted :)

S/MIME has very little adoption - the kind of people who care about encrypting their email are usually the same kind of people who don't trust the CA system.

That's not true: https://gist.github.com/rmoriz/5945400
Post reply on HN