Live data from Hacker News

21 years after the request OpenPGP support gets added to Thunderbird

bugzilla.mozilla.org

261–270 of 281 posts

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#261

Earlier quoted context omitted.

I was born 20 years ago...

It would have been hilarious if you'd fixed this bug... :-)

Now that you mention it, I'm surprised I can't think of any example of someone fixing a software bug that is older than them. (I'm assuming Warner Losh is older than 35).

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#262
post #209

Earlier quoted context omitted.

because gnupg is not the only implementation.

Yes, that's what I said, and why I was asking! What does the OpenPGP format bring to the table, BESIDES HAVING A COMMONLY AVAILABLE IMPLEMENTATION IN GNUPG?

It's the generic term.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#263
post #160

Earlier quoted context omitted.

Autocrypt is the middle ground Thunderbird should have implemented (and which Enigmail used to offer). Email is here to stay, so encryption by default won't happen as long as the PGP standard is used as designed (trust levels and all). Autocrypt improves all that horrible UX, including secure key transfer or rotation, where you can keep doing your own key management if you wish, but you have to do nothing more than e…

From what I've read, PGP for Thunderbird is just a first step. My guess is that they chose the easiest/quickest path for first implementation, but I think we'll see more facilitation of encrypted email in TBird in time. This makes sense to me. I've been trying to get friends, family and colleagues to encrypt email (hell, even signing would be a step!) for about 3 decades, now, and have basically thrown in the towel.…

The Autocrypt plugin was that toehold for me. Together with a mobile client like K9mail it works beautifully.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#264
post #246

Earlier quoted context omitted.

You can't just "Nope" this issue. You need to come up with some sort of rational argument. The PGP people have been dealing with the data at rest issue since forever. It is a bit presumptuous to just write off all that acquired wisdom without reason.

I have come up with a rational argument, you just refuse to address it at all. Your argument boils down to 'the PGP people are smarter than everyone else' which I think isn't really even a rational argument.

There is no reason to appeal to authority here when a simple koan can provide enlightenment. I will repeat it one more time:

How do you do a downgrade attack on, say, an encrypted backup?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#265

Earlier quoted context omitted.

When we nitpick, "country" = geographic unit, "state" = political unit. The United States is itself a state, albeit a federation of smaller states.

This is a nice distinction, actually. It means we can think about "stateless countries" (like Western Sahara, perhaps), and "countryless states" (like the Sovereign Military Order of Malta).

Stateless countries are also those that cross state borders. Example: Kurdistan, Ireland.

And conversely, there are states spanning (parts of) more than one country: The UK with North Ireland and many others (perhaps England, Scotland and Wales if you consider them separate countries).

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#266
post #246

Earlier quoted context omitted.

I have come up with a rational argument, you just refuse to address it at all. Your argument boils down to 'the PGP people are smarter than everyone else' which I think isn't really even a rational argument.

There is no reason to appeal to authority here when a simple koan can provide enlightenment. I will repeat it one more time: How do you do a downgrade attack on, say, an encrypted backup?

No. We've got a threadful of arguments here in which you simply refuse to engage. You don't get to superciliously demand Socratic satisfaction, wave around your list of logical fallacies and mumble oracularly about koans and enlightenment. You have to make an argument otherwise what you're doing is simply rude preening. It's fine if you have nothing to say. You don't get to (at least, publicly) pretend you've actually said anything and that it's everyone else who has to meet your precise terms of discussion. Sorry.

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#267
post #248

Earlier quoted context omitted.

Key management is a burden in every cryptosystem. I'm using KeePass and can recommend it, it works well.

Would you know if it failed?

If it would "fail" and there would be no consequences so I could't tell if it failed or not - would it make a difference?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#268
post #266

Earlier quoted context omitted.

There is no reason to appeal to authority here when a simple koan can provide enlightenment. I will repeat it one more time: How do you do a downgrade attack on, say, an encrypted backup?

No. We've got a threadful of arguments here in which you simply refuse to engage. You don't get to superciliously demand Socratic satisfaction, wave around your list of logical fallacies and mumble oracularly about koans and enlightenment. You have to make an argument otherwise what you're doing is simply rude preening. It's fine if you have nothing to say. You don't get to (at least, publicly) pretend you've actuall…

This all started when you said something to the effect that "packet oriented formats" were bad. When asked to clarify you switched the topic to how flexibility in cryptography was bad because it could lead to downgrade attacks. I pointed out that downgrade attacks were not really possible in a data at rest application and that the article you linked to was about data in flight applications.

That's it. That's the actual arguments to this point. Then you just said nope.

You are not claiming that logic and facts are irrelevant here, are you?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#269

Earlier quoted context omitted.

I have a different perspective. I think that the scope of the 2nd amendment has narrowed over the years. In 1776, private citizens owned every kind and sort of weapon used by the military. Ordinary people owned cannons, were instructed to put cannons on their private ships to defend against pirates, and owned the same sorts of muskets used by the army. The modern equivalent would be buying tanks at Walmart for cash a…

> By the way, the archaic meaning of "regulated" means "properly disciplined and drilled". It did not refer to control or supervision by a state. That still leaves open the question of what levels of discipline and drilling the (federal or state) government could demand of someone for them to be included in the Militia. It is already accepted that felons and the mentally ill may be prevented from exercising 2nd Amend…

The government cannot demand anything. The well-regulated part is a justification clause.

Imagine if the 2A said this: > "A well tailored suit, being necessary to a sharply dressed citizenry, the right of the people to keep and wear clothing, shall not be infringed."

Does this mean that the government now has a right to force dress codes on people so that their suits are well tailored?

Also justification clauses have been used in other contemporary laws too:

> Retrospective laws are highly injurious, oppressive and unjust. No such laws, therefore, should be made, either for the decision of civil causes, or the punishment of offences. (From NH Ex Post Facto Article)

Does this mean that ONLY when the ex-post facto laws are injurious, oppressive and unjust, should that law be unconstitutional according to the NH constitution?

Re: 21 years after the request OpenPGP support gets added to Thunderbird

#270

Earlier quoted context omitted.

My high school friends and I settled for using Gain and Pidgin to enable the "secure" icon. :)

Ah, the good old days when I could just plug my IM services into one desktop app. I miss those days very much. Now I use three Electron apps on a typical work day.

I still use Pidgin for Skype and Hangouts. For text only it's perfect:

- https://aur.archlinux.org/packages/purple-hangouts-git/ - https://aur.archlinux.org/packages/purple-skypeweb-git/

Works even on old and crappy computers.

Post reply on HN