3 ms·
Using PGP securely is as easy as downloading some software, typing in your message, and clicking a button. It's not something that requires any knowledge beyond
by ocb 11y ago
Using PGP securely is as easy as downloading some software, typing in your message, and clicking a button. It's not something that requires any knowledge beyond basic computer usage. You aren't going to be able to stop people from sharing PGP software on the internet.
I think you're severely underestimating the intelligence of people in general. If we're talking about ISIS, all it takes is one moderately experienced computer user to show everyone else how to use PGP.
- DanBC 11y ago> Using PGP securely is as easy as downloading some software, typing in your message, and clicking a button. It's not something that requires any knowledge beyond basic computer usage. You aren't going to be able to stop people from sharing PGP software on the internet. And yet we find a bunch of supposedly encrypted stuff where the user did something wrong, leaving the stuff effectively unencrypted. See also people uploading keys to github etc.
- Joeboy 11y agoWhat software are you talking about? I've seen very clever people struggle with PGP. In fact Ed Snowden famously screwed up when he first emailed Glenn Greenwald.
- ocb 11y agoGPGTools, for example (https://gpgtools.org https://gpgtools.org) I suppose I omitted the step of copying and pasting your recipient's public key, but that's not especially conceptually difficult, either.
- Joeboy 11y agoThat does look quite nifty. There's also keypair generation, which is the step that derails most people I think. Plus the fact that people have to grok the concept of public and private keys, and be able to distribute / not distribute them as appropriate. And revocation certificates. And public keyservers. And trust levels. Etc. I do think an organised, disciplined group might manage to get PGP working as intended, but I doubt there are many such groups. My point is, I doubt individuals implementing encryption have much to fear from whatever proposals may emerge from this. Maybe they will later. But it seems to me it's much more likely to target companies that offer/facilitate encrypted messaging. Edit: Thanks to whoever just put my karma over 2000. Does anything exciting happen when you get to 2000 points?
- ocb 11y agoHmm. I guess my thought is that if it became well-known that using Whatsapp, iMessage, etc. to communicate about illegal activities frequently led to arrest, then knowledge of PGP and the like would spread because it's not too difficult to use. So then government would be able to read everyone's communications through those channels for no appreciable benefit. Obviously, that's total conjecture, though.
- nailer 11y agoUsing PGP is as easy as understanding PKI, which is beyond most people that don't work in tech, and a substantial amount of people that do.