Two things that would make this have more hope of becoming a standard: 1) open source the key server with the REST-API 2) allow domain owners to define their own key server via a DNS TXT entry
1. What's wrong with the existing key server protocol? 2. Why TXT and not SRV?
Making PGP Key Management Invisible So Johnny Can Encrypt
71–78 of 78 posts
Re: Making PGP Key Management Invisible So Johnny Can Encrypt
#72Does keys.whiteout.io gossip with other HKP keyservers? If so, is there any documentation on the gossip protocol? I can't seem to find any, and the SKS keyserver is the only implementation of the gossip protocol that I can find.
Yes. It gossips with the following list of servers. Keys are uploaded and also fetched form these servers: ' https://pgp.mit.edu' , ' http://pool.sks-keyservers.net' , ' http://keys.gnupg.net' , ' http://keyserver.ubuntu.com' , ' http://pks.gpg.cz'
Re: Making PGP Key Management Invisible So Johnny Can Encrypt
#73Earlier quoted context omitted.
I'd be really, really cautious about throwing "No True Scotsman" at Seth David Schoen and Erinn Clark. https://en.wikipedia.org/wiki/Seth_Schoen His hopelessly out-of-date homepage: http://www.loyalty.org/~schoen/ That said, yes, PGP has a notable failing in that there's no reliable method for repudiating a key, particularly one generated by a hostile party. If you've hung on to your key revocation certificate you ca…
PGP is fine. People aren't using it correctly. The point of Web of Trust is to only trust keys that other people you know have also signed. Everything else is garbage until proven otherwise. Key servers are untrustworthy because anyone can upload random shit to them. Trying to shift WoT to a third party is trying to get something for free that doesn't emphasize solving the problem: getting everyone you know signing k…
Re: Making PGP Key Management Invisible So Johnny Can Encrypt
#74Earlier quoted context omitted.
I'm sorry my homepage is out of date; thanks for the reminder. It seems like it's been a decade or so since I updated it. I normally check signatures when downloading a new key, particularly as a way of distinguishing between multiple keys available on a keyserver. But I don't have a way to force other people who are writing to me to do that, and apparently at least the Enigmail users often don't. Edit: Erinn is a mo…
I check up on you from time to time. Virtunova's been offline for ages as well. I'm kicking around ways of making email more reliable, one option that occurs to me is key negotiation at transmit time, or as part of the delivery process. That is: a user's home mailserver would be key-aware. Though that too is subject to skulduggery. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -----BEGIN PGP MESSAGE----- Version: G…
-----BEGIN PGP MESSAGE-----
Version: GnuPG v1.4.11 (GNU/Linux)
hQIMA6PfwQZKAOF/ARAAkzfxMj8XnsmBmGu3uxS6cp/0q1xE/U89sTLlVZmDbwna
IGOXkm1h6DId7Hvwnj+RjYRj/wym3kvrMCXoOPLpqr0y2kGcBxxcW0kdK+zhlz34
ik+Vy+HGp0MZKog6HnBiMotnDZuYJsxZhPE++XSZDj8N/16XNXmvDjuDZTlkvKUm
UX0y8kem2uSN8WjGuQepF2zwwzL8LDjJ7x9RemDgfudkiNkSUQVDz2WNwrrXssR4
g4cRTs0wUaRYa/xDUXvum/uHxOJ/ZF/cEKMB9oXBIw4m+1VHTzLJYz3PFwFHiib3
SWnJ90tm2vjKsp9Q1VQYa8zyINOzDDGMbLP7OgkDU5/nvGFxLflRyvYwVoHkyKuW
Ar/5vHxdf0F4vgJuJHJIieuQcSVv06pvFczmnbQmO9vLMBvRti++Vu2u2olyoyr9
5cgZ+I/AvNXjPN8u3IiyT+6/bwXAT41G6nUZWs7xfqEvX5RFQA4dh/qkjuHpDUWx
ROVzgdqvLpnsO2uZ2Y0++ETuer0aYpqSo03oOb2bNsXdlZF1SSu7dNfSzJv47J5e
yFn5Wn4hK1TswuRYKDy3HGk0au0NSdNfDi83YR17N1xQg5heK1Daf73DWZRnxOPi
EnDHc17Uha3nN+FIKm1JdwxA4T35eJl0pa2S9SPWmHUNWvMwCLC4JqR0Br8Yx8TS
aQGmENhVRPMX73uPo8SDn+M6u0PvJ7pWPKn3ulcwwrMgqSf4qgptozB8g0vTr3YJ
k40OdHO7ebcWN5wkw2dg9tIFFgxnqrpjB7vr0aHJj3Y96AYoD0uSrEiBgX6pIJdz
jGWswAp7O5UfGw==
=DT21
-----END PGP MESSAGE-----Re: Making PGP Key Management Invisible So Johnny Can Encrypt
#75Re: Making PGP Key Management Invisible So Johnny Can Encrypt
#76Earlier quoted context omitted.
If you want to avoid being in a dragnet, just requiring TLS using policies on your SMTP server is enough. That's what many organizations do already. If you just want "encryption" as a checkbox, then just use Gmail with everyone and your data isn't going anywhere outside Google anyways. I'm wondering who the users are that have threat models that make them concerned about attackers able to compromise, say, Google, but…
You are not seriously suggesting that Gmail is perfectly private, are you? You must have missed how the NSA was tapping between Google's servers. http://www.washingtonpost.com/world/national-security/nsa-in... End to end encryption is safe, mail server to mail server leaves your mail unencrypted on an unknown number of servers. If those are in the US or a similarly crazy country, they are just one letter away from be…
The NSA story is a nice addition, but tales of the FBI carnivore system reading all email by connecting at big interexchanges is decades old, yet no one is taking even that part seriously.
Re: Making PGP Key Management Invisible So Johnny Can Encrypt
#77Earlier quoted context omitted.
If you want to avoid being in a dragnet, just requiring TLS using policies on your SMTP server is enough. That's what many organizations do already. If you just want "encryption" as a checkbox, then just use Gmail with everyone and your data isn't going anywhere outside Google anyways. I'm wondering who the users are that have threat models that make them concerned about attackers able to compromise, say, Google, but…
You are not seriously suggesting that Gmail is perfectly private, are you? You must have missed how the NSA was tapping between Google's servers. http://www.washingtonpost.com/world/national-security/nsa-in... End to end encryption is safe, mail server to mail server leaves your mail unencrypted on an unknown number of servers. If those are in the US or a similarly crazy country, they are just one letter away from be…
The NSA story is a nice addition, but tales of the FBI carnivore system reading all email by connecting at big interexchanges is decades old, yet no one is taking even that part seriously.
Re: Making PGP Key Management Invisible So Johnny Can Encrypt
#78The key discovery part seems unobjectionable, and vastly cleaner than what keybase.io does. Looking at their design for key sync[0], though, maybe I'm just dense, but I swear I read the article, and I still can't tell -- what's the advantage of this complicated thing with a symmetric key over just protecting the private key with a strong passphrase and sticking it in Dropbox? [0]: https://blog.whiteout.io/2014/07/07/…
We're currently in the process of simplifying the key sync spec. The new version will store your private key encrypted with a strong random passphrase in IMAP. So it's similar to your dropbox proposal, but with a UX that leads users along the way.