Earlier quoted context omitted.
> What we need is a system that allows people to easily create new IDs, that updates contacts that people choose. > Contacts would need to be always online. That also sounds impractical. > It's a required ID to use the internet How does any of that follow? Having a reusable self-sovereign ID format for those scenarios where people want to share it is very different from having an authority-issued ID format that's man…
If the ID is permanent then governments will require it, because they can. If it has attestations or endorsements, governments will require a government endorsement. Think about what China, Iran or Russia would do with a permanent ID being a standard. The US, England and the EU are not immune to the same impulses. Always online is no different than an email account or website, and the rate of change would be, at leas…
Are we self-sovereign PKI yet?
61–70 of 92 posts
Re: Are we self-sovereign PKI yet?
#62Earlier quoted context omitted.
And yet many of the highest risk systems that exist, the whole foundation of the internet, several governments, major corporations, and thousands of high risk individuals rely on it because centralized options will never be agreed to by all parties, for good reason. I have lost count of the orgs I have personally trained to use PGP properly in recent years. In spite of your claims, PGP solves the problem it was desig…
That's a weird thing to say. Yes, it is? What are you claiming is different about it? In fact, there are ways in which it has regressed from 2016's incarnation.
A renewed IETF working group that aggressively deprecated legacy ciphers and mandated modern ones with optional PQ crypto support (RFC 9580). Lots of actively developed rust implementations like rPGP, rsop, rpgpie, sequioa. Easy key provisioning and backup with smartcard support via keyfork. Smartcards with rust firmware by Nitrokey. Modern key distribution and trust bootstrapping via openpgp-ca, hagrid, keyoxide, etc.
GnuPG is admittedly garbage, but also that has not been a valid implementation of PGP specifications for a while and no one should use it anymore. PGP != GPG
I would strongly suggest taking a hard look at the last decade of thankless work going on to modernize the PGP ecosystem we all rely on directly or indirectly.
Currently writing up the above and a lot more in detail to refute years of outdated rhetoric on this topic so we can start having more useful conversations about it.
Re: Are we self-sovereign PKI yet?
#63Earlier quoted context omitted.
That's a weird thing to say. Yes, it is? What are you claiming is different about it? In fact, there are ways in which it has regressed from 2016's incarnation.
Where even to begin. A renewed IETF working group that aggressively deprecated legacy ciphers and mandated modern ones with optional PQ crypto support (RFC 9580). Lots of actively developed rust implementations like rPGP, rsop, rpgpie, sequioa. Easy key provisioning and backup with smartcard support via keyfork. Smartcards with rust firmware by Nitrokey. Modern key distribution and trust bootstrapping via openpgp-ca,…
Having a bunch of implementations of an omnibus package that tries to be a crypto swiss army knife, written almost exclusively without the input of cryptographers, is actually not a desirable goal.
Re: Are we self-sovereign PKI yet?
#64Take my money.
(Care of randomly shuffled https://spacesprotocol.org/faucet/)
Re: Are we self-sovereign PKI yet?
#65Earlier quoted context omitted.
That's a weird thing to say. Yes, it is? What are you claiming is different about it? In fact, there are ways in which it has regressed from 2016's incarnation.
Where even to begin. A renewed IETF working group that aggressively deprecated legacy ciphers and mandated modern ones with optional PQ crypto support (RFC 9580). Lots of actively developed rust implementations like rPGP, rsop, rpgpie, sequioa. Easy key provisioning and backup with smartcard support via keyfork. Smartcards with rust firmware by Nitrokey. Modern key distribution and trust bootstrapping via openpgp-ca,…
Got it.
Re: Are we self-sovereign PKI yet?
#66Earlier quoted context omitted.
Where even to begin. A renewed IETF working group that aggressively deprecated legacy ciphers and mandated modern ones with optional PQ crypto support (RFC 9580). Lots of actively developed rust implementations like rPGP, rsop, rpgpie, sequioa. Easy key provisioning and backup with smartcard support via keyfork. Smartcards with rust firmware by Nitrokey. Modern key distribution and trust bootstrapping via openpgp-ca,…
It's thankless because it's a bunch of folks at the county fair running around putting lipstick on all the pigs. Having a bunch of implementations of an omnibus package that tries to be a crypto swiss army knife, written almost exclusively without the input of cryptographers, is actually not a desirable goal.
This fragile network we all use is made of a mountain of pigs that continually need their lipstick reapplied by people that do it for free or near free out of a desire to keep the whole thing running for everyone.
Said people even do it for the users that stay at safe distance pointlessly saying "We should go back in time and build it differently in unspecified ways!".
Re: Are we self-sovereign PKI yet?
#67Earlier quoted context omitted.
It's thankless because it's a bunch of folks at the county fair running around putting lipstick on all the pigs. Having a bunch of implementations of an omnibus package that tries to be a crypto swiss army knife, written almost exclusively without the input of cryptographers, is actually not a desirable goal.
And none of the back seat drivers ever have alternatives to suggest that solve the same problems while having bothered to endure the IETF standardization process, and thus PGP will continue to be the trust foundation of the software supply chain of the internet for the forseeable future. This fragile network we all use is made of a mountain of pigs that continually need their lipstick reapplied by people that do it f…
Or that the replacements being aren’t as concerned as you are with the IETF process?
Re: Are we self-sovereign PKI yet?
#68Earlier quoted context omitted.
Where even to begin. A renewed IETF working group that aggressively deprecated legacy ciphers and mandated modern ones with optional PQ crypto support (RFC 9580). Lots of actively developed rust implementations like rPGP, rsop, rpgpie, sequioa. Easy key provisioning and backup with smartcard support via keyfork. Smartcards with rust firmware by Nitrokey. Modern key distribution and trust bootstrapping via openpgp-ca,…
"It's great! You just have to not use the de facto standard implementation everybody uses." Got it.
Re: Are we self-sovereign PKI yet?
#69Earlier quoted context omitted.
Where even to begin. A renewed IETF working group that aggressively deprecated legacy ciphers and mandated modern ones with optional PQ crypto support (RFC 9580). Lots of actively developed rust implementations like rPGP, rsop, rpgpie, sequioa. Easy key provisioning and backup with smartcard support via keyfork. Smartcards with rust firmware by Nitrokey. Modern key distribution and trust bootstrapping via openpgp-ca,…
"It's great! You just have to not use the de facto standard implementation everybody uses." Got it.
Just like IE6, GnuPG abandoned the global standardization processes and in doing so forced an expensive migration to successors.
Global changes on the internet take decades in part because of all the people far removed from the process spreading outdated information and demanding we give up on standards and move the whole world to centralized solutions that do not even solve the same problems, like Java Applets, Adobe Flash, or Signal.
Meanwhile those standardizing and rolling out longer term solutions roll their eyes and keep doing the work.
Re: Are we self-sovereign PKI yet?
#70Earlier quoted context omitted.
"It's great! You just have to not use the de facto standard implementation everybody uses." Got it.
GnuPG is not the final say for PGP any more than IE6 was the final say for the web. Migrating off IE6 took a while and so will migrating legacy systems off GnuPG. New users of PGP are thankfully mostly using new gen reasonably secure tools. Just like IE6, GnuPG abandoned the global standardization processes and in doing so forced an expensive migration to successors. Global changes on the internet take decades in par…
I'd pose this challenge to you: find the most reputable cryptography engineer or academic cryptographer you can find that believes this is a good idea. I'd be interested if you could find even one. Fair warning: some of my confidence talking down PGP comes from knowing what the conventional wisdom among cryptographers is about the PGP cryptosystem.