Live data from Hacker News

The PGP problem (2019)

latacora.com

31–40 of 121 posts

Re: The PGP problem (2019)

#32
post #5

The biggest issue with PGP/gpg is the difficulty of getting rid of it. If you work on big distros, or know someone who works on big distros, please (start asking them to) add https://github.com/jedisct1/minisign to pre-installed packages to facilitate transition. It's almost a chicken egg problem but the sad thing is, no project wants to swap the signing tool to a better one until everyone can verify the new signatur…

Note that minisign was also vulnerable in the gpg.fail exposures

All software has bugs. But having a small purpose-built program do one thing well is much smaller attack surface. The Unix philosophy also makes a pretty good security argument.

Re: The PGP problem (2019)

#34
post #19

I agree that age + minisign comprise a much neater stack that does basically everything I would need to use PGP for. Neither of them supports hardware keys though, as much as I could see. OTOH ssh and GnuPG do support hardware keys, like smart cards or Yubikey-like devices. I suppose by the same token (not a pun, sadly) they don't support various software keychains provided by OSes, since they don't support any exter…

BTW apparently age has plugins that allow to use FIDO2 and TPM for cryptography.

Re: The PGP problem (2019)

#35
post #31

Earlier quoted context omitted.

[flagged]

I don't care that it's a tangent, I care that it's incoherent and wrong.

The tangent explicitly talks about generic messaging services. Whatsapp and Signal have more money than gpg. Thinking about it more, it is not even a tangent, because TFA says:

"Use Signal. Or Wire, or WhatsApp, or some other Signal-protocol-based secure messenger."

Re: The PGP problem (2019)

#36
post #19

I agree that age + minisign comprise a much neater stack that does basically everything I would need to use PGP for. Neither of them supports hardware keys though, as much as I could see. OTOH ssh and GnuPG do support hardware keys, like smart cards or Yubikey-like devices. I suppose by the same token (not a pun, sadly) they don't support various software keychains provided by OSes, since they don't support any exter…

> Neither of them supports hardware keys though, as much as I could see.

https://github.com/str4d/age-plugin-yubikey

Re: The PGP problem (2019)

#37

[flagged]

> Of course, people here who have recommended Signal are silent about these issues and rather continue to bash gpg.

I've reviewed Signal extensively on my blog. https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...

I analyze cryptosystems based on what an attacker can do, given sufficient capabilities.

"The user adds the wrong person to a group chat" is not a cryptographic weakness, nor a particularly interesting one. Why would I have anything to say about it?

We aren't "silent" about your pet peeves. We just have lives and more interesting things to talk about.

> EDIT: tptacek enters the chat, my messages are downvoted. This is how he convinces people to use Signal.

This kind of comment gets people banned from Hacker News. Please stop that.

Re: The PGP problem (2019)

#39

[flagged]

> Of course, people here who have recommended Signal are silent about these issues and rather continue to bash gpg. I've reviewed Signal extensively on my blog. https://soatok.blog/2025/02/18/reviewing-the-cryptography-us... I analyze cryptosystems based on what an attacker can do, given sufficient capabilities. "The user adds the wrong person to a group chat" is not a cryptographic weakness, nor a particularly inter…

Of course you omit the QR code issue in your response, just like tptacek tried to deflect in the other subthread after his Cryptocat objection was refuted.

Re: The PGP problem (2019)

#40

Earlier quoted context omitted.

> Of course, people here who have recommended Signal are silent about these issues and rather continue to bash gpg. I've reviewed Signal extensively on my blog. https://soatok.blog/2025/02/18/reviewing-the-cryptography-us... I analyze cryptosystems based on what an attacker can do, given sufficient capabilities. "The user adds the wrong person to a group chat" is not a cryptographic weakness, nor a particularly inter…

Of course you omit the QR code issue in your response, just like tptacek tried to deflect in the other subthread after his Cryptocat objection was refuted.

> Of course you omit the QR code issue in your response,

What? You mean a vulnerability that was mitigated in February of last year? In what sense am I obligated to comment on such a thing? You use the verb "omit" as if such an obligation exists. This is delusional rhetoric.

First you complain about tptacek choosing to comment about a tangent, and then you get upset that I didn't entertain your tangent. Pick a lane.

> just like tptacek tried to deflect in the other subthread after his Cryptocat objection was refuted.

I didn't see a refutation.

Post reply on HN