4 ms·
> have you ever tried to forward a PGP message? I believe this is a solvable UI / UX problem; what you are in fact criticizing is not the OpenPGP format of asy
by wfn 10y ago
> have you ever tried to forward a PGP message?
I believe this is a solvable UI / UX problem; what you are in fact criticizing is not the OpenPGP format of asymmetric keys, but rather the conventional implementations of PGP, based around GPG. I agree that GPG is not very user-friendly for the use cases at hand; but surely things can be improved on this front while not ditching the general PGP model itself?
edit as to the more technical issues, e.g. lack of PFS, core issue of initializing WoT, the defaults in the PGP format etc., yes, they suck, but surely one could iterate on the UX side of things, abstracting all internals behind a more general PGP API, and later gracefully changing the internals themselves, too? Not saying it's a piece of cake or anything!
- nbadg 10y agoTo your first point: I agree that it's not the key format that's the problem with forwarding -- so, you could use a PGP key definition for a different message format that worked better, and as long as you ignored all of the extra stuff in a PGP public key definition, it's no harm no foul. At its core, it's just a public key. But that's not what breaks forwarding, the actual message format does, and that isn't just a UI/UX problem. You must personally decrypt and re-encrypt the message against the public key of the person you're forwarding it to, and if the original author signed it you then need to somehow encapsulate the signature (which is outside of PGP spec), and then you're still left with the key distribution problem, which becomes exponentially more difficult with each tome the message is forwarded. That's not just a UI/UX problem, that's also a fundamental technical failing of the PGP message. PGP is incompatible with social. That's not to say, by any stretch of the imagination, that these are unsolvable problems. Quite the opposite, actually; I hope at the very least that my company has made some decent progress down the road to solving them. I'm saying only that PGP simply isn't the vehicle to take us there, because it is (in my experience) a very poor design for general-purpose usage (especially social). To your edit: unfortunately PGP encapsulation is really, really poorly situated to construct general-purpose abstractions on top of. It just doesn't work with reused (ie forwarded, replied, etc) data. Building an abstraction facade on top of that to ease transition to a new format, though technically possible, is definitely infeasible: both your storage requirements and computation requirements are going to increase linearly with each reuse of existing data (meaning it would grow exponentially with the number of shares, assuming the worst case, that everyone re-shares it).