4 ms·
What does the average user do when they forget their passphrase? (Which they will do constantly.) How do you determine the keys associated with the people you
by timdierks 11y ago
What does the average user do when they forget their passphrase? (Which they will do constantly.)
How do you determine the keys associated with the people you wish to communicate with? (The web of trust and going to key-signing parties are about a thousand miles from 'everything just works'.)
- dave2000 11y agoWhat happens if you lose control of your private key? How do you ensure the recipient keeps up to date with which keys have been revoked? Isn't it a risk that unless you keep changing keys you're at risk of someone getting your private key and having access to every message you've ever received?
- oceanofsolaris 11y agoTo be honest, I don't even see the point of setting a separate passphrase for your PGP on a machine you own if it adds any hassle for you [1]. I don't see why you PGP key should be so different from every other password you use. Sure, PGP does not have forward secrecy, but neither does gmail if someone grabs your password. I agree with you that if you want to actually improve the security of the people who are right now not using any encryption, make encryption easy to use. Even if this means that it might not fit the threat-model of those targeted by state-actors. IMHO, PGP could actually be used for this (even if it might not be the perfect fit) by using Trust On First Use, better interfaces and more integration into mail clients. The problem is that it is right now a tool used and made by those who want really strong security. This includes e.g. encouraging you to set a passphrase, which makes it more secure, but also more of a hassle for most people. [1] This is obviously only true if you don't fear it being compromised / your security requirements are low. But then, if you need strong security, use full disk encryption and Qubes or something similar.