Live data from Hacker News

GPG and Me

thoughtcrime.org

81–90 of 267 posts

Re: GPG and Me

#81

These rants are not very useful until one of the two geniuses (Green, Moxie) can come up with a comfortable solution to the core problem of key distribution. And given that nowadays Green seems completely consumed by twitter while Moxie believes in fixing whatsapp, I wouldn't hold my breath.

Could you further ID "Green"? Do not know who that is.

Edit. Matthew Green?

Re: GPG and Me

#82
Articles (and the attendant discussions) like this are incredibly useful for me. I really appreciate HN for things like this.

Recently signed up for keybase to check it out. Read critiques (mostly negative) but jumped in anyway as I am hungry for something like it. I do not have a deep grasp of the arguments but I see the 'lipstick on a pig' criticism of slapping a gui on an aging infrastructure.

The practical problem with keybase for me is finding people to test it out with. I've added folks who don't know me and my friends couldn't care less.

There is a blindspot for me - I use ssh and rsa on a daily basis, many times a day. I do not know what I would do if I has to switch to something else. I do not know how to evaluate security options and know to know one is better than another.

We have very good infosec people in my company and have a standing weekly meeting to vet my sysops doings.

In any event will check out Whisper Systems and keep refreshing this discussion...

Re: GPG and Me

#83
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

You know you're one of only a few people in the world who is in a position to do that, right? Anyone else would (rightfully!) get torn to shreds on HN by tptacek or yourself. And I say "rightfully" because it is very likely that other people would screw up some central aspect to the security of any new product that claims security. It's not just that, though. Anyone else with your knowledge but no standing would be s…

Is there a kick starter page for this cause that I can contribute to? Because I would.

I'm not going to back just any crypto project, but with the right people leading the charge I would get behind it.

Re: GPG and Me

#84
post #81

These rants are not very useful until one of the two geniuses (Green, Moxie) can come up with a comfortable solution to the core problem of key distribution. And given that nowadays Green seems completely consumed by twitter while Moxie believes in fixing whatsapp, I wouldn't hold my breath.

Could you further ID "Green"? Do not know who that is. Edit. Matthew Green?

Matthew D. Green, the "expert in applied cryptography and network security" who was invited to take a look at the Snowden-stash but declined because he was scared. Which is funny, because since Snowden he became some sort of web-celebrity always ready to tweet and comment on every little crypto/security issue.

Re: GPG and Me

#85
I'm working on a GPG replacement that is designed to be super-easy to use. Not quite ready for prime time but if any HNers would like a sneak preview drop me a line. Contact info is in my profile.

Re: GPG and Me

#86
post #54

Earlier quoted context omitted.

> Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. Identity and authentication are the biggest reason that PGP hasn't caught on with non-technical users - the web-of-trust is necessary to do distributed identity and authentication properly (under the current model), and the importance of out-of-band verification can be hard to explain. Authentication…

There's no other model than the web-of-trust. And it didn't fail because it's hard to grap (it's really not), it failed because a) almost no one needs it and b) the tech is hard to use. Imagining a world where the web-of-trust was succesful is not hard. It starts with everyone using Outlook instead of gmail. Then imagine Outlook having PGP support builtin. Then imagine in the contacts list, every contact was marked w…

At the risk of being inappropriately snarky, to someone who is somewhat skeptical of WoT-based proposals, this reads like:

Step 1: the UI will be a mixture of meaningless and annoying to users, causing them to ignore and misuse it

Step 2: mumble mumble... self-healing corruption

Step 3: the only reason this hasn't succeeded is that people didn't care enough

It's exactly those parts in step 2 where I've historically fallen off of the WoT story. What does the UI do when my nontechnical friend has marked my key but his dad has marked it as untrusted? What happens when I lose my phone with my keys on it? How do we not end up in a situation where users see big scary warnings all the time constantly and they just learn to ignore them?

Re: GPG and Me

#87
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

Back in the 90's I tried to use GPG, and I tried to pay for digital music. They both went roughly the same way. Arguably it was easier to use GPG back then than it is now. Pine was my MUA and I had an easy to find public key. Now I have an iPhone, don't use Linux on my laptop anymore, and make heavy use of messaging products. Here's what I have now that I didn't have then, 2FA. There's an app on my phone that makes i…

>Perhaps this will all change because before Snowden we were blissfully unaware

Every time I see this in regards to email, I'm puzzled. Carnivore was known about in the 90s. Then there was the AT&T Room 641A in the 200s. So I don't know how people were unaware that state level actors could tap connections and record email.

Second, for this threat model, just forcing and validating TLS on SMTP gets you pretty far, does it not? You're then mostly trusting your email provider. And without trusting them, we get into user-unfriendly stuff like not being able to forget your password. (Barring some sort of breakthrough ideas.)

Seriously, has there been any good proposals that provide strong privacy (say, no one but the user can read the message) but aren't complicated or require users to do things they aren't gonna do: validate keys? PGPFone and ZRTP are great because you already have an "out-of-band" key auth mechanism in place, and it's fairly straightforward to check.

Re: GPG and Me

#88
post #54

Earlier quoted context omitted.

> Peter Todd suggests that PGP drop encrypted communications as a goal and focus only on identity and authentication. Identity and authentication are the biggest reason that PGP hasn't caught on with non-technical users - the web-of-trust is necessary to do distributed identity and authentication properly (under the current model), and the importance of out-of-band verification can be hard to explain. Authentication…

There's no other model than the web-of-trust. And it didn't fail because it's hard to grap (it's really not), it failed because a) almost no one needs it and b) the tech is hard to use. Imagining a world where the web-of-trust was succesful is not hard. It starts with everyone using Outlook instead of gmail. Then imagine Outlook having PGP support builtin. Then imagine in the contacts list, every contact was marked w…

> There's no other model than the web-of-trust.

SPKI & SDSI had a different model: rather than trust people to tell you who someone is, one trusts them to tell you who they think they are. That is, rather than me verifying that key 0xDEADBEEF belongs to the individual known to the town council of Lower Shroppington as 'William Morris' (which is inherently fragile: I may not be an expert at verifying identity documents, or at verifying those issued by Lower Shroppington; the individual before me might have a document issued by Lower Shroppington deliberately to mislead me; heck, who is the real William Morris: there could be more than one), I would just verify that this is the individual I call William Morris, and let you make use of that as you may. If Lower Shroppington wanted to, they could issue a certificate stating that they call him William Morris too.

It was a really smart way of doing things.

How might it fit into a modern email infrastructure? Easy! example.com could use key 0xBADDA451 use certify that foo@example.com belongs to the keyholder of the key 0xC0FFEEBA; .com could use key 0xFEEDBAC7 to certify that example.com belongs to 0xBADDA451; the root domain could use key 0x55378008 to certify that .com belongs to 0xFEEDBAC7; IANA could certify the ownership of the root domain; the ICANN board could certify the current IANA key; the previous ICANN board could certify the current ICANN board, and so forth.

What would you see in Outlook or Gmail? Your agent would display that the claimed sender email is valid. It might also try to find some path connecting you & good ol' Bill Morris, then show you that your buddy Steve's ex girlfriend Wilhelmina says that key belongs to Billy Morris.

Interestingly, this could even work for an email legitimately sent on William's behalf. All a normal user would care about is, 'this email is legit' (for some value of); us geeks could geek out as we wished.

Re: GPG and Me

#89
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

The issue is that it seems like you want to replace GnuPG by something that does the same - but is made better, and that has your brand name on it.

That's very marketingish of you. Why not fix GnuPG instead? There's more than slapping GUIs to things!

Also, where is your 50K user base number from? According to my SKS keyserver traffic, it's much greater, even if i were to assume 50% of the traffic is non-human.. what the fuck happened to you man?

Also, if it's well done - I'm not against something different from GnuPG. I just disagree with the argument.

Which leads to this question:

which product are you going to announce in 6mo that would be so much better?

Re: GPG and Me

#90
post #48

A lot of the comments I've been getting are in the genre of "well... but GPG works." Yes, GPG is a powerful tool that makes some encrypted communication possible . But is it really "working" if it's the tool we've had for the past 20 years, and we still ended up in a world where surveillance is so ubiquitous and privacy is so rare? Having used GPG, it seems more likely to me that there are only ~50k GPG users in the…

What do you think that looks like, though? Is it TextSecure on the desktop, with file attachments? Is it Pond? Is it just email, but with a different crypto layer? I feel like a lot of the things GPG aims to do are fundamentally hard. It's not the technology that sucks, it's the problem . I completely agree that the answer will come from thinking about user interactions first, but I'm not sure that the solution will…

I don't have a definite answer. There's the path we're executing on at Open Whisper Systems, but there are a bunch of other projects working in this area as well (Mailpile, LEAP, etc).

I think the problems are solvable, but only if we have a different design approach. So when I see projects trying not-PGP, I'm interested. When I see projects building on PGP, I'm less interested.

Post reply on HN