Live data from Hacker News

The PGP Problem

latacora.micro.blog

361–369 of 369 posts

Re: The PGP Problem

#361
post #326
post #316

Earlier quoted context omitted.

I'm not sure what you mean. :(

I'm suggesting that the Yubikey experience isn't exactly flawless. I use Qubes too, but I don't think everyone should have it as a daily driver. If you want to use Yubikeys for SSH, that's fine. IF you want to use Yubikeys for GPG, you have many of the problems outlined in the post. Does that clarify?

Ah, I can somewhat agree with that. But I have doubts any experience is flawless.

Though, I did mean my yubikey use is for gpg. I have considered otp uses of it. But primarily use it for supporting pass, which is gpg.

Re: The PGP Problem

#362
post #120

Earlier quoted context omitted.

I'm a little confused as to why you mention Signal and WhatsApp but not Telegram?

Telegram invented it's own crypto, without an audit it's untrustworthy. There's only Signal and Keybase that has been audited, so Whatsapp should be excluded from the list of trustworthy IM apps as well.

"without an audit"

It would be more accurate to say that they have failed every attempted audit of the protocol.

Re: The PGP Problem

#363
post #83

First of all, if you are signing something and want to prove that you are the author, then PGP will allow you to do that. If you want to encrypt something and prove you are the author, PGP will still allow you to do that. Does the author mean that PGP is bad for email specifically? Excel has many of the mentioned properties, such as backwards compatibility and inefficiency, but it gets the job done and you bet it wil…

Yeah, most (all) of these arguments seem silly. The primary argument not to use it in emails because someone MIGHT improperly quote your email in a reply and then NOT encrypt their response? Well someone might screenshot your Signal app, or have malware on their phone, or a million other things. It seems like such an absurd corner case to me. For my use case I don't have any concerns about using GPG. I encrypt files…

Not because it "MIGHT" happen, because it does happen.

Re: The PGP Problem

#364

Whent talking about alternatives, Signal and WhatsApp get mentioned because they're easy to use. They are. Signal is pretty secure. WhatsApp probably is as well but we can't be sure. That is, until it isn't anymore. WhatsApp already has a key extraction protocol built right in for its Web interface. Signal has a web (Electron) interface as well, and a shitty one at that, where the messages also get decrypted. For Wha…

Just FYI, Actalis will mint you a free S/MIME cert. https://www.actalis.it/products/certificates-for-secure-elec...

Where they generate your private key :(. I rather let them sign my own key

Re: The PGP Problem

#365
post #16
post #11

Earlier quoted context omitted.

Matrix works, and has fairly easy-to-use clients (and I've switched a few non-technical folks without too much trouble). It's also an open protocol, not just an app. The main criticism (and I'm preemptively responding to tptacek here) is that they haven't yet made E2EE the default (though this should happen in a few weeks now that cross-signing appears to be done). I also think the key backup system should be much be…

Use Matrix if you want to contribute to Matrix or are an enthusiast about what Matrix is trying to do. But don't use it as a secure messenger, or tell at-risk people to use it. It may someday be a serious option for secure messaging, but it is not that today. I'm not a Matrix hater, but I think Matrix's cheering section gets the project in trouble, since their answers about privacy and security are demonstrably worse…

> Use Matrix if you want to contribute to Matrix or are an enthusiast about what Matrix is trying to do. But don't use it as a secure messenger, or tell at-risk people to use it.

Also replying to this (likely too late!) in the hopes of a little clarification. In particular, "don't use it as a secure messenger" seems like strange advice in view of the fact that there don't seem to be any better options. That is to say, there are no options that fulfill all three of these requirements:

1. Full support for group chat with end-to-end encryption between all participants. (Matrix even includes cryptographic controls on how much history is shared, though that's not a requirement.)

2. Completely open source with no centrally controlled servers.

3. Does not require any PII (including a phone number) to begin using.

As far as I know, every messenger fails on at least one of these counts, and many fail at all three. It's one thing to criticize Matrix (there are a lot of things about it that suck right now, to the point that I'd never recommend it to a casual user), but to do so without any alternative doesn't seem helpful.

Have I missed something better?

Re: The PGP Problem

#366

Earlier quoted context omitted.

I think that currently Keybase.io is the only thing trying to be universal, with their transparency log plus links to external profiles along with signed attestations for them. But even that's still not quite what I'm looking for. There's no straightforward way to link arbitary protocol accounts / identities to it, outside of linking plain URL:s. We need something a bit smarter than keybase that would actually allow…

Also, as I looked a little bit into Keybase I learned that they don't support any protocols that don't have public profile-like pages. So a pure messenger wouldn't be supported by Keybase.

They're opening up the protocol so that any website can provide the authentication, and Mastodon already implements it: if you have an account on Mastodon, you can have an additional proof on keybase.

See the blog post and the spec that details the changes to implement: https://keybase.io/blog/keybase-proofs-for-mastodon-and-ever...

I presume a pure IM system would have to implement some web gateway at the server level.

Re: The PGP Problem

#367
post #363

Earlier quoted context omitted.

Yeah, most (all) of these arguments seem silly. The primary argument not to use it in emails because someone MIGHT improperly quote your email in a reply and then NOT encrypt their response? Well someone might screenshot your Signal app, or have malware on their phone, or a million other things. It seems like such an absurd corner case to me. For my use case I don't have any concerns about using GPG. I encrypt files…

Not because it "MIGHT" happen, because it does happen.

I mean "might happen" in any particular instance. Not that it has never happened and only "might" in the future. Because 0.000000000000000000000000001% of messages have been accidentally exposed does not make PGP inherently bad.

Re: The PGP Problem

#368
post #51
post #47

Earlier quoted context omitted.

Signal does a great job of supporting activists. That's basically its intentional product focus. Everything an open source proponent engineer might want to promote is secondary. The focus on activism and trying to deal with large actors definitely looks like #1. Everything else about their product is secondary to that. Signal's product focus has been at best un-encouraging to those who want to use it for anything els…

The byzantine packet format in PGP buys PGP nothing. There is no engineering reason for PGP to work that way, and PGP continues to suffer security issues because of it. I'm not arguing that PGP's original designers were incompetent, nor am I considering that argument, because it is totally uninteresting to me. What is relevant to me is the fact that today, that design is costly and bad. What more is there to think ab…

You make a good point. The design is costly and bad, I hope I wasn't arguing to retain it for historical reasons or anything like that. I do believe that the history of how PGP got there, and how its ecosystem became the sort of hydra that it is should be kept in mind for anyone trying to build a replacement.

The commercial factors that drove the engineering there I think is a real risk for any cryptosystem implementor, especially if they are trying to build or retain a userbase.

Re: The PGP Problem

#369
post #362

Earlier quoted context omitted.

Telegram invented it's own crypto, without an audit it's untrustworthy. There's only Signal and Keybase that has been audited, so Whatsapp should be excluded from the list of trustworthy IM apps as well.

"without an audit" It would be more accurate to say that they have failed every attempted audit of the protocol.

I'd love to read more about this, could you please provide a few links?
Post reply on HN