I used to love PGP, but I now think encrypted email is a bad idea. https://latacora.micro.blog/2020/02/19/stop-using-encrypted.... Better to use a protocol designed with encryption in mind, like Signal, to get forward secrecy, avoid leaking metadata, and have encryption always on by default. UPDATE: I have been reminded that PGP does not have to be used with email. I meant to say that I used to love using PGP with em…
21 years after the request OpenPGP support gets added to Thunderbird
241–250 of 281 posts
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#242Earlier quoted context omitted.
I see your point, but as a non-American who's flooded with videos of random Americans walking around supermarkets carrying semiautomatic rifles, I'm not sure what you mean with "tightly regulated militia".
It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…
By the way, the archaic meaning of "regulated" means "properly disciplined and drilled". It did not refer to control or supervision by a state.
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#243Earlier quoted context omitted.
A slightly more realistic "dead simple solution" might be for mail clients to extend their OpenPGP support to include Autocrypt[0] which would allow users to gain some of the advantages of OpenPGP without having to understand any of the details. [0] https://autocrypt.org/
Interesting. In my opinion, this should also contain provisions for storing the private key password-encrypted on the IMAP server.
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#244Earlier quoted context omitted.
How do you do a downgrade attack on, say, an encrypted backup?
I guess I don't understand how that's a response to anything I've written in this thread. Edit: I'll expand the quote from the original thing a bit if it helps: (Open)PGP is first and foremost a flexible packet format (and other specs), and GnuPG is more of a CLI "library" to interface with it -- all of it. You can build something that hides metadata, you can have forward secrecy, and encryption always-on by default…
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#245Earlier quoted context omitted.
Maybe so, but then we need to come up with more words. As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.)
> As the UK proved, a nation in the EU is free to leave the EU, but a state in the US is not. (Without consent of the US, of course.) Which article or amendment of the U.S. Constitution forbids a state to leave without permission of the U.S.?
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#246Earlier quoted context omitted.
I guess I don't understand how that's a response to anything I've written in this thread. Edit: I'll expand the quote from the original thing a bit if it helps: (Open)PGP is first and foremost a flexible packet format (and other specs), and GnuPG is more of a CLI "library" to interface with it -- all of it. You can build something that hides metadata, you can have forward secrecy, and encryption always-on by default…
You can't just "Nope" this issue. You need to come up with some sort of rational argument. The PGP people have been dealing with the data at rest issue since forever. It is a bit presumptuous to just write off all that acquired wisdom without reason.
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#247Earlier quoted context omitted.
OpenPGP is used to secure everything from simple messages and email to authenticating OS updates for most servers today. And for MOST of the places that it is used, it gets screwed up in some way that makes it not as secure as the people using it thought that it was. Stop and think carefully about that statement. And repeat it to every person you meet who thinks that they are solving their problems with OpenPGP.
What do you mean by PGP "not [being] as secure as the people using it thought that it was"? Can you mention something specific?
Due to the complexity of the PGP system, there are a plethora of downgrade attacks. Where something that was supposed to be at one level of security can be tricked into doing something much less secure. See https://twitter.com/xmppwocky/status/1291144278953955328, https://mailarchive.ietf.org/arch/msg/openpgp/JLn7sL6TqikUf-..., and https://www.eff.org/deeplinks/2018/05/pgp-and-efail-frequent... for three different examples of such attacks against PGP in recent years.
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#248Earlier quoted context omitted.
I use pass and I would switch in a heartbeat to a fork of it that used ssh keys or something similar instead of gpg. For something so amazingly simple and useful, its dependence on the klunky mess that is gpg key management is an anchor that weighs it down.
Key management is a burden in every cryptosystem. I'm using KeePass and can recommend it, it works well.
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#249Earlier quoted context omitted.
What do you mean by PGP "not [being] as secure as the people using it thought that it was"? Can you mention something specific?
Here is something specific. Due to the complexity of the PGP system, there are a plethora of downgrade attacks. Where something that was supposed to be at one level of security can be tricked into doing something much less secure. See https://twitter.com/xmppwocky/status/1291144278953955328 , https://mailarchive.ietf.org/arch/msg/openpgp/JLn7sL6TqikUf-... , and https://www.eff.org/deeplinks/2018/05/pgp-and-efail-freq…
The second one is just yet another person discovering that the MDC check can be stripped off a message.
The third one seems to be just EFAIL which is not a downgrade or any attack really against PGP.
Re: 21 years after the request OpenPGP support gets added to Thunderbird
#250Earlier quoted context omitted.
It's a joke. The text of the 2nd amendment is slightly ambiguous. Many people (myself included) believe that the intent of it was to protect citizens' right to arm themselves, but only in the context of being a member of a state-run/regulated militia. Unfortunately SCOTUS has continually widened the scope of 2A over the years. > as a non-American who's flooded with videos of random Americans walking around supermarke…
Texas isn't like that either. I've lived in Texas for almost a decade and I've never seen someone open carrying a long rifle at the supermarket. Geez, the stereotypes people spread!
But yeah, there are vanishingly few places in the US where you should expect to be in the presence of gun-toting civilians while doing something as mundane as grocery shopping.