3 ms·
Please correct me if I am wrong, but as I understand it in GPG's case perfect forward secrecy simply cannot be used. PFS can be used in frameworks where the two
by giomasce 10y ago
Please correct me if I am wrong, but as I understand it in GPG's case perfect forward secrecy simply cannot be used. PFS can be used in frameworks where the two parties interact and can use DH or similar protocols to establish an ephemeral session key. In GPG models the two parties do not interact: the first one produces a ciphertext and the second one decrypts it possibly a lot of time later. In this model the plain text is by definition a function of the ciphertext and the secret key. The only way to circumvent it would be to change how maths work.
So, I do not think that GPG can be declared broken because it does not have PFS. It simply is targeted at use cases where this does not make sense (and there are valid examples of such use cases). If it is used in wrong ways or in context where other encryption schemes would be more suitable, then this is a user's fault. I cannot really understand what the article's author is proposing about fixing GPG problems.
- giomasce 10y agoBTW, by GPG I actually meant OpenPGP. The tool itself may have shortcomings, but everyone is welcome to write another one that uses the same standard and works better.