I don't agree. I use GPGtools on OSX with the openpgp smartcard and it works flawlessly and is truly convenient. Furthermore I can use 4096 bit RSA keys. One thing I have learned watching the crypto forums over the years is that there are well calculated misinformation campaigns trying to dissuade people from using secure methods. I see it again and again and the people on this forum need to think carefully before sw…
What's the matter with PGP?
61–70 of 166 posts
Re: What's the matter with PGP?
#62I'm using TextSecure on my Android phone as a Messaging replacement and it is great. However it appears to me that the service is not decentralised in any way. Is that assumption correct? I like the email model such that anyone can install and run an email server. I'd actively push friends, family and colleagues to use a decentralised email replacement that was as easy to use and secure as TextSecure.
Re: What's the matter with PGP?
#63I don't agree. I use GPGtools on OSX with the openpgp smartcard and it works flawlessly and is truly convenient. Furthermore I can use 4096 bit RSA keys. One thing I have learned watching the crypto forums over the years is that there are well calculated misinformation campaigns trying to dissuade people from using secure methods. I see it again and again and the people on this forum need to think carefully before sw…
You talk bad about RSA and use RSA keys at the same time?
Re: What's the matter with PGP?
#64I don't agree. I use GPGtools on OSX with the openpgp smartcard and it works flawlessly and is truly convenient. Furthermore I can use 4096 bit RSA keys. One thing I have learned watching the crypto forums over the years is that there are well calculated misinformation campaigns trying to dissuade people from using secure methods. I see it again and again and the people on this forum need to think carefully before sw…
You talk bad about RSA and use RSA keys at the same time?
Re: What's the matter with PGP?
#65Earlier quoted context omitted.
I'm all for that, but realistically how will you verify identity? If there is no identity verification what is stopping me from going out and registering for "google.com" and then using it in my MITM attack?
I think most non-EV SSL certificates these days are "verified" by sending a message to whatever e-mail address you have on file in your whois record. Also on Chrome at least certificate pinning should prevent that particular scenario.
As to the whois thing, what is stopping me from hijacking a domain, changing the whois and then generating keys? The webadmin might never even know. You don't even need access to their email.
Or to put it more realistically: What is stopping the NSA from pressuring a domain registrar into altering the whois for a brief period in order to generate MITM keys?
Re: What's the matter with PGP?
#66But for some reason (maybe because it's generally less life-threatening), people seem to expect deeply complex subjects, like e-mail encryption and identity management, to be easy. "Yeah, if you can just give me a fancy, easy-to-use GUI with forward secrecy, that'd be great!" Sure, it'd be great. But it's not going to happen. And that's not because PGP is broken -- of course, it does have its weak points. It's because people are too lazy to bother to learn.
What's the old addage? You can have quick, cheap and reliable. Pick two? Same here. You can have secure, easy to use, and reliable. Pick two.
Re: What's the matter with PGP?
#67Even in it's long form, it's relatively easy to generate different keys that have the same fingerprint.
Re: What's the matter with PGP?
#68Just a random thought - maybe there is a way to nail hard the point that "you cannot have security if you're lazy"? The society expects people to do driving licenses before getting behind the wheel. Why not expect people to put some amount of effort to be able to get mortgage or interact with court, etc.? Sure, many people will screw this up, but maybe this will be enough to secure majority. (confession: I myself am…
Counter example: I'm not too lazy to use HTTPS. Maybe if email encryption was more like HTTPS more people would use it? Just transparent and easy.
Sure, but the point of a lot of comments here seems to be that It Can't Be Done.
Re: What's the matter with PGP?
#69> Except maybe not: if you happen to do this with GnuPG 2.0.18 -- one version off from the very latest GnuPG -- the client won't actually bother to check the fingerprint of the received key. Even in it's long form, it's relatively easy to generate different keys that have the same fingerprint.
Re: What's the matter with PGP?
#70Earlier quoted context omitted.
I think most non-EV SSL certificates these days are "verified" by sending a message to whatever e-mail address you have on file in your whois record. Also on Chrome at least certificate pinning should prevent that particular scenario.
Chrome's certificate pinning database doesn't scale at all (i.e. it works on less than 0.01% of the internet). As to the whois thing, what is stopping me from hijacking a domain, changing the whois and then generating keys? The webadmin might never even know. You don't even need access to their email. Or to put it more realistically: What is stopping the NSA from pressuring a domain registrar into altering the whois…