3 ms·
There was a ton of FUD around PGP and encryption export legalities and commercial use. There was a window to make this stuff standard 20 years ago and we, as t
by tacos 10y ago
There was a ton of FUD around PGP and encryption export legalities and commercial use.
There was a window to make this stuff standard 20 years ago and we, as technologists, totally whiffed on it.
The "these are not web technologies" quip at StackExchange made me cringe for some reason. As if this has anything to do with web protocols.
For the sordid history:
https://en.wikipedia.org/wiki/Pretty_Good_Privacy https://en.wikipedia.org/wiki/Pretty_Good_Privacy
For yet another sadly ignored, co-opted, would-be-standard:
https://tools.ietf.org/html/rfc4880 https://tools.ietf.org/html/rfc4880
- atonse 10y agoMaybe – but I still think the problem with tools like PGP are the user experience, and not any underlying tech. If you look at things like WhatsApp and iMessage, they give you the same kind of security in a completely transparent way. And I believe Whisper/WhatsApp also give you a cool way to verify keys in person (I believe they use QR codes?) So public key crypto is here, and it's widespread. It's just not in the form of PGP, and that's because of the UX shortcomings of PGP. On a side note, Keybase really is awesome – I have setup keybase and am hopeful for it, but I feel even in that case, if you try to do PGP, it feels a bit odd.
- mikekchar 10y agoIt's not just the UX. A very good example: what does "signing a key" mean? You've got public/private key pairs (both of which are called "keys" in some places), you have a master "key" and sub "keys". The master key is called "the key" but doesn't actually contain the sub keys (which are also called "keys". When you sign a "key" what actually gets signed? (Hint: not a key) Where does the signature go? Etc, etc, etc. The Open PGP protocol is just insanely complicated because it took many different iterations to get right and they didn't want to break backward compatibility. The documentation that tries to explain it is downright wrong because they don't want to go down the rat's nest that is the protocol. So even most technically savvy users have absolutely no idea what's going on. Unfortunately, it can't really be fixed with UX, IMHO. I think we need to learn from Open PGP and design something that doesn't make people's heads (even programmers) explode.
- atonse 10y agoYeah honestly I'm curious as to why Keybase is using PGP – is it really that widespread, or is it that PGP is so hardened with time? I know the keybase devs lurk around here. Is there perhaps a way to use the Signal Protocol instead of PGP?
- nickpsecurity 10y agoIdk about Keybase but I recommended GPG because it was one of only three or so tech the NSA couldn't break per Snowden leaks. They were smashing most stuff. So, my recommendation was modifying proven code to put a better UI on it that ignored most of the complexity to focus on just fundamental features. Note: Keybase with with their own PGP implementation. Idk what its security is going to be like. I see why they'd use tech that's had years of auditing and attacks, though.