Live data from Hacker News

Facebook Is Ending Support for PGP Encrypted Emails

joltmailer.com

51–60 of 69 posts

Re: Facebook Is Ending Support for PGP Encrypted Emails

#51
post #32

Earlier quoted context omitted.

> and we developed plenty new needs like verifying software signed by random people on the other side of the globe, while GPG did nothing to accommodate that use That's actually a really common use-case for GPG. I've seen it used for this more than for email...

I mean sure, there's a bunch of developers out there signing their code with GPG. But have you actually tried verifying it properly? To verify the tor browser correctly, you need a trust path. Option A: You've met at least one of them directly, and for some reason decided to sign a key with the label "Tor Browser Developers" on it. How did that person prove to you that they're a legitimate Tor developer? That's a pre…

I don't agree, it's dead simple:

For your example,

1. Download the software form the official website.

2. Verify the signature.

3. Done. If you are very concerned, you can double check the signature from a previous version from the Way back Machine.

What are the chances the official site AND the archive were both compromised?

Re: Facebook Is Ending Support for PGP Encrypted Emails

#52
post #42
post #31

It's possible to solve both the friction to start and stop using PGP by looking up keys automatically on the target domain, for example using WKD [1]. We (Proton) host a key for every user, which can be used to automatically end-to-end encrypt emails to all Proton Mail users, without any setup needed, nor risk of DoS (since the user can always remove their key from WKD). Various other providers also offer this [2]. […

Proton user here: I’ve an anecdote because it happened this week and support was unable to help me. I’ve received a PGP encrypted email by a non-proton user. It worked fine. But I was unable to encrypt my reply to him. Proton support told me that he needs to attach his public key to his message so I can use it. It seems that the Proton interface doesn’t offer any way to automatically try to find the public key of an…

We do look up keys automatically using WKD. However, if the non-Proton user's provider doesn't support that, they'll indeed have to attach it or you'd have to import it manually.

We have plans to also look up keys on keys.openpgp.org as well, to offer an automatic solution in case the provider doesn't support WKD.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#53
post #48
post #31

It's possible to solve both the friction to start and stop using PGP by looking up keys automatically on the target domain, for example using WKD [1]. We (Proton) host a key for every user, which can be used to automatically end-to-end encrypt emails to all Proton Mail users, without any setup needed, nor risk of DoS (since the user can always remove their key from WKD). Various other providers also offer this [2]. […

This would be so useful to verify Maven PGP keys. Is there any sort of integration with that? If not, I am thinking of writing that.

I'm not aware of anything, but I'm also personally not that familiar with Maven, apologies.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#54
post #52
post #42

Earlier quoted context omitted.

Proton user here: I’ve an anecdote because it happened this week and support was unable to help me. I’ve received a PGP encrypted email by a non-proton user. It worked fine. But I was unable to encrypt my reply to him. Proton support told me that he needs to attach his public key to his message so I can use it. It seems that the Proton interface doesn’t offer any way to automatically try to find the public key of an…

We do look up keys automatically using WKD. However, if the non-Proton user's provider doesn't support that, they'll indeed have to attach it or you'd have to import it manually. We have plans to also look up keys on keys.openpgp.org as well, to offer an automatic solution in case the provider doesn't support WKD.

Thanks for the clarification. I now understand better: I was confusing WKD and keys.openpgp.org as same thing.

As I received the email without the key attached and his domain doesn’t support WKD, I was stuck to manually import from keys directory. It makes sense.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#55

Earlier quoted context omitted.

I mean sure, there's a bunch of developers out there signing their code with GPG. But have you actually tried verifying it properly? To verify the tor browser correctly, you need a trust path. Option A: You've met at least one of them directly, and for some reason decided to sign a key with the label "Tor Browser Developers" on it. How did that person prove to you that they're a legitimate Tor developer? That's a pre…

I don't agree, it's dead simple: For your example, 1. Download the software form the official website. 2. Verify the signature. 3. Done. If you are very concerned, you can double check the signature from a previous version from the Way back Machine. What are the chances the official site AND the archive were both compromised?

Then you're using it wrong. GPG isn't adding anything to this that SHA256 wouldn't, and you're just relying on the SSL certificate.

Look at your list of CAs sometime. There's multiple national organizations there. Controlled by a government.

And any of those will be deemed as valid, so if you go to https://www.torproject.org/download/ and it's signed by a Chinese CA for some reason, to your browser that's perfectly fine.

> What are the chances the official site AND the archive were both compromised?

You're talking about a piece of software that's designed to hide stuff from state level actors. If you're in actual need of such a thing, that threat is pretty damn serious.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#56

Earlier quoted context omitted.

> I suspect this was a state actor funded operation, for this has effectively, and significantly reduced the usefulness of PGP/GNUPG. If it was, they did us all a favour, because PGP as means of encrypting emails is a steaming pile of garbage, as it requires both, client support, and the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else) Email was never meant t…

> PGP as means of encrypting emails is a steaming pile of garbage, as it requires [...] the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else) All encrypted communication protocols have this requirement. And all of them will in the future. By definition, you need the counterparty to be able to decrypt your message, which means you're always vulnerable to them f…

> which means you're always vulnerable to them forwarding the unencrypted message to anyone they want.

email makes this trivial.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#57

Earlier quoted context omitted.

> PGP as means of encrypting emails is a steaming pile of garbage, as it requires [...] the counterparty to have the same OPSEC as you (e.g. not just forwarding the email unencrypted to someone else) All encrypted communication protocols have this requirement. And all of them will in the future. By definition, you need the counterparty to be able to decrypt your message, which means you're always vulnerable to them f…

> which means you're always vulnerable to them forwarding the unencrypted message to anyone they want. email makes this trivial.

No more trivial than any other method. Once you have the plaintext, you can send copies to whoever you want, by whatever means you want.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#58
post #2

Presumably the is no overlap in the Venn diagram of people who want PGP encrypted emails and people who use Facebook,

Once upon a time I tried to adapt Mailvelope to encrypt FB messages, for what it's worth. But that was a long, long, LONG time ago. https://mailvelope.com/en/

I used mailvelope for the longest time as a gmail user until I found a better mail app with gpg support. It was pretty slick last time I used it.

Shamefully I also turned on the pgp messages from Facebook. I never found value with it, but to this day it’s still enabled and I don’t care to log in to Facebook to disable it.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#59
post #2

Presumably the is no overlap in the Venn diagram of people who want PGP encrypted emails and people who use Facebook,

It’s at least a small intersection. I had it set up and I think it’s the only social media company that supported this.

Comically I forgot all about it until I had to reset my password and got an encrypted email. Was a pain to dig out my keys and decrypt it, but it worked.

Re: Facebook Is Ending Support for PGP Encrypted Emails

#60
post #36

Earlier quoted context omitted.

Github asks you to log in again to add SSH keys in, this could've been similar They're just looking for excuses

A lot of account compromise is due to reused passwords so I'm not sure that's a complete solution.

The point is that much more sensitive things exist online and it's a solved problem
Post reply on HN