Facebook and PGP
41–50 of 60 posts
Re: Facebook and PGP
#42While I'm cautious about facebook in general, it is (in essence) a repository for public data. A public key falls into that category, so they gain nothing more than the association of user and key. And in return, the PRISM databank has more superbly useless information to store and eventually 'collect' for 1EF communication.
And I gain immunity from account hijacking unless I mess up Key Management.
Re: Facebook and PGP
#43Earlier quoted context omitted.
A little of topic, but if someone would like a invite to keybase let me know :-)
For anyone late, I have 9 invites. My details are on keybase: https://keybase.io/lekevicius
Re: Facebook and PGP
#44The last paragraph of the linked post describes more or less what keybase [1] is. [1] https://keybase.io/
A little of topic, but if someone would like a invite to keybase let me know :-)
Well that and they don't solve the only really interesting problem with GPG: how to send a secure email to somebody who doesn't yet have a private key.
Re: Facebook and PGP
#45Earlier quoted context omitted.
Well, from what I know there are some seriously privacy minded people in there. As oxymoronic as that sounds. But I could certainly see some benefits both for FB and for world at large from this. One of the big problems with PGP is how to bootstrap web of trust. "Does this key really belong to this particular person?" But what if the otherwise loathed real name policy could be turned to service this particular need?…
Zuckerberg actually cares a lot about his privacy . Yours? Maybe not as much. http://www.slate.com/blogs/business_insider/2015/05/18/tech_... http://www.theguardian.com/technology/shortcuts/2015/may/19/... But isn't the PGP move a sign that Facebook cares about our privacy? Not really. The profile thing makes it easy to discover people who use PGP and email them with encrypted messages, but that has nothing to do wit…
I guess the prevailing notion (as the grand parent said) is that while Facebook couldn't give two shits about our privacy, there are people who work there who do care about privacy in general (and not just their own privacy). Of course, no Facebook employee is going to come out publicly and call Mark Zuckerberg for being a self-serving psychopathic douche bag.
[1] (owned by Facebook, I imagine the deal is complete by now)
[2] https://whispersystems.org/blog/whatsapp/
> The most recent WhatsApp Android client release includes support for the TextSecure encryption protocol, and billions of encrypted messages are being exchanged daily. The WhatsApp Android client does not yet support encrypted messaging for group chat or media messages, but we’ll be rolling out support for those next, in addition to support for more client platforms. We’ll also be surfacing options for key verification in clients as the protocol integrations are completed.
> WhatsApp runs on an incredible number of mobile platforms, so full deployment will be an incremental process as we add TextSecure protocol support into each WhatsApp client platform. We have a ways to go until all mobile platforms are fully supported, but we are moving quickly towards a world where all WhatsApp users will get end-to-end encryption by default.
Re: Facebook and PGP
#46Payments (bitcoin style currencies), banking, document signitures, and single sign-on?
Re: Facebook and PGP
#47The easy answer is that they knew Apple was going to come out strong for encryption in the past few days and wanted to do a "me too."
Re: Facebook and PGP
#48Earlier quoted context omitted.
Well, from what I know there are some seriously privacy minded people in there. As oxymoronic as that sounds. But I could certainly see some benefits both for FB and for world at large from this. One of the big problems with PGP is how to bootstrap web of trust. "Does this key really belong to this particular person?" But what if the otherwise loathed real name policy could be turned to service this particular need?…
> But what if the otherwise loathed real name policy could > be turned to service this particular need? The link between a real person and a Facebook account isn't secure - I could make an account with your name today without too much stress (no need to provide ID unless Facebook thinks your name isn't a real name).
Sure, you can register an account in my name, but there are quite a number of people who will not be fooled: people who actually know me. People who know me in real life can tell whether an account is real or not, because they can tell whether I post about things I do, whether I post pictures that are...well, me.
In that case, they can be reasonably sure that the account in question is, in fact, my account. If I attach my GPG key to this account, they can thus also reasonably assume that the GPG key belongs to the account that belongs to me. This essentially gets you the online equivalent of a key-sharing party.
Re: Facebook and PGP
#49The last paragraph of the linked post describes more or less what keybase [1] is. [1] https://keybase.io/
1. They tell you to trust webpages which claim that their code does not send passwords or private keys to the server – something which would be extremely hard to verify now and even were you to do so now, could silently change in the future:
https://www.dropbox.com/s/teikzwftimeu8nc/Screenshot%202015-...
https://www.dropbox.com/s/1xlvpd8drhix0tj/Screenshot%202015-...
2. They encourage blindly copying and pasting complex commands into a shell:
https://www.dropbox.com/s/5rv7p4mks0qdr7f/Screenshot%202015-...
I have no reason to believe they're doing any of this in malice but it's not good because it encourages people to believe claims which could be made by any phisher and encourages practices which put you at risk if Keybase is ever compromised.
The answer to this, of course, would be a browser-managed crypto API which could provide unspoofable UI indicating that e.g. a private key will never leave the client but in the absence of such an API it feels irresponsible to make similar claims which aren't actually possible.
Re: Facebook and PGP
#50Has anyone got an encrypted email from facebook yet? I uploaded my key and ticked the box, but the last notification I got was still in the clear.
If you click that verification link, you'll receive a web notification that it's enabled should start receiving encrypted notifications.
Check your spam folder in case your mail provider's or client's spam filter is mislabeling it.
If you don't see it, try unchecking and rechecking the opt-in box, which should trigger a new verification email. (We've had a feature request for a "Resend" button".)