Live data from Hacker News

Felony – An open-source PGP keychain

github.com

221–230 of 241 posts

Re: Felony – An open-source PGP keychain

#221
post #213
post #211

Earlier quoted context omitted.

> That has nothing to do with PGP. You could do the same by base64-ing an OTR session (in fact, people do that all the time). But PGP also works for printing stuff on a post-card (or you know, email) - asynchronous communication. While Axolotl does push OTR-like modes towards asynchronous use - they do involve a lot more than getting hold of a public key (say, one published in a magazine, or shown in a frame of a mov…

If you don't need PFS (which you should need) then you can use DH to create the shared key you use for the HMAC. Maybe you could even do an original OTR-like ratchet scheme (only change the key once the recipient shows that they are using the new key) to get PFS. But in principle if you assume that key distribution is "solved" then you can implement the unique parts of OTR.

I'm not sure, you're saying the format and message standards of PGP of providing machine-readable signed keys aren't worth anything, because you can just memorize some base64 coded secrets and run with it?

That's how you'd prefer to bootstrap secure communication with a journalist, or for recruiting people to demonstrate against the current regime in Egypt?

> But in principle if you assume that key distribution is "solved" then you can implement the unique parts of OTR.

How can it make sense to think of it as solved? How do you backup your keys? Your list of trusted keys? Protect them against theft? Alert others to their compromise? Get alerted when keys are compromised?

Key distribution really is the only really interesting problem in secure, trusted, communication (with secure one time pads, most problems go away. The trick is to make sure you have secure one time pads, shared only with the person(s) you want to communicate with...).

Public key encryption opens up some new ways to make the problem easier, but it's just one step in the right direction.

Re: Felony – An open-source PGP keychain

#222
On a related note, has anyone had a look at "Pretty Curved Privacy" ?

https://github.com/TLINDEN/pcp

(Just submitted it to hn - I thought there was an old submission, but apparently I was mistaken): https://news.ycombinator.com/item?id=12035081

If felony is PGP protocols wrapped in modern web technology, I suppose pcp is NaCl wrapped in old PGP command line and protocols...

Re: Felony – An open-source PGP keychain

#223

Earlier quoted context omitted.

You seriously can't do this yourself? Clone the repo and change the name using find-and-replace and run install. No need to insult.

Sorry, did not mean to insult. Just stating how I interpreted the name. There seems to be a number of forks already (currently 12).

Many people will fork just to keep a backup.

Re: Felony – An open-source PGP keychain

#225

Hi I'm Henry, the creator of Felony I’ve had a passion for politics, history, and programming since the age of 12 growing up in a suburb of Chicago. During my freshman year, I developed an interest in software. A couple of apps and hackathons (programming competitions) later, I was working on my own startups when I made the leap to drop out of high school to become a software engineer at a venture-backed tech startup…

Is it geared to mobile devices? The screenshot looks very much like one from a mobile. I wouldn't trust my phones underlying security architecture enough to store a PGP private key on the device.

PS: I love the name. You did a good job with it creating a buzz. It made me laugh and curious enough to take a look. Maybe pointing out on your site that "privacy is a human right" and the name should remind us of that rather than succumbing to peer-pressure, in the hope of not offending the 0.01% of your non-tech savvy users.

Re: Felony – An open-source PGP keychain

#227

This name is awful. I would never want to contribute to it, nor use it. Nor suggest it to anyone as a solution to anything. It's the worst name since that framework called "cocaine" with tools and subprojects named after illicit drug market terms. Yeah, "felony" and "cocaine" are not things I will put on my CV or would like to show up when someone Googles my name. What's the joke here? That some people are incorrectl…

>Do you know what most "felons" did to be called that? It's not for what they said and wrote that should be constitutionally protected. Exercised journalistic integrity and protected an anonymous sources? http://uscode.house.gov/view.xhtml?path=/prelim@title18/part... The press is free, as long as it doesn't protect sources that have leaked embarrassing information about the armed forces.

Is that how most felons earned their felony conviction?

Because that's what I asked (rhetorically).

Re: Felony – An open-source PGP keychain

#228
post #129

Earlier quoted context omitted.

The satire writes itself. What's wrong with .org/.net?

Not trendy. I would always prefer .net over .io though, but I'm oldschool.

Clearly you are just another corporate Java and Microsoft drone!

Re: Felony – An open-source PGP keychain

#229

Earlier quoted context omitted.

Just curious: Are you running on a Raspberry Pi or other machine with constrained resources? 130MB is less than 4% of the memory in most modern computers, and less than 10% of most mid-range phones.

Just to be nice i'll assume you ask earnestly and answer earnestly: I have 16 GB of RAM. However i also always have more than one app running at any given time. In fact, my system usually has 200+ things running. I also don't mind if things use a lot of memory if: They either use it to give me a lot of bang for my buck, or are not long-running processes. Felony ticks neither of these boxes. Also do keep in mind that…

I didn't realize Felony was a long-running process. I thought you just open it when you want to process some messages, then close it when you're done.

Re: Felony – An open-source PGP keychain

#230
Call it "privatebits" or something more suggestive that personal informational boundaries and privacy can be healthy for everyone, rather than the highest criminal offense. I understand that there's some irony or sarcasm there, but trust me, those are not timeless, even for people who "get it". Bitter humor is not sustainable in the long run, so relying on that kind of energy probably won't help the cause.
Post reply on HN