13 ms·
I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practi
by psiconaut 10y ago
I find very interesting the point about the split between what WoT was supposed to be, in theory, and what little it represents, in practice, in terms of practices about key verification.
It has been said many times that the lack of adoption of pgp in mail was due to the average user not being able to grasp the concepts behind the proper operation for key management, but the article points to common practices among "power users" that will drop the theoretical best practices and switch to fallback, unsecure modes, given the effort needed to properly verify a key binding. If the community that cares about encryption and privacy is not able to routinely verify keys, the whole system definitely has a weak link.
I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here.
And to me, assuming that the most usable thing we can use instead is something that relies on mobile phone identifiers, more often than not tied to a phisical world identity, is really something to worry about.
- jerf 10y ago"I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here." I think it's the key model that's fundamentally flawed rather than pgp itself, which I believe the author of the article is also asserting. In cryptography, it is often explained that despite the fact a one-time pad is guaranteed-secure (given various conditions I'm eliding), it is not practical in the vast majority of cases because of a chicken-and-egg problem: How do you distribute the one time pad in the first place? If you do it insecurely, it's a waste of time. If you can do it "securely", why not just use that secure channel to send the message in the first place? OTPs can still be useful because you can establish a secure channel once for a limited duration of time and then use it to temporally shift your security into the future, but that's a relatively rare use case. (That is, the vast bulk of encryption is being used between people who may never have had a "secure" channel between them; think HTTPS here.) Similarly, PGP's got this significant problem where given that you have the correct keys and that you know you can trust them, it secures your communication quite effectively. But the question is, how do we get to the point where you know that you have the correct keys and you can trust them? Well... that's a hard problem itself. Especially considered over time. So alternate models must be pursued. Like the author, I think the Keybase approach is a good idea. In fact I'd even suggest that the idea should be generalized away from "social media accounts" to just "potentially unreliable mechanism" in general. If I have 6 mechanisms for asserting identity on my key, each of which are 95% reliable over the course of a year, then from an absolutist security point of view, that key is still insecure... but assuming even modest independence between the unreliable mechanisms (assuming naive total independence is definitely incorrect, once one is hacked the others are certainly more likely, but neither is it the case that one hack guarantees all others can be hacked), it's still much more secure than nothing at all.
- coldpie 10y ago> Like the author, I think the Keybase approach is a good idea. In fact I'd even suggest that the idea should be generalized away from "social media accounts" to just "potentially unreliable mechanism" in general. It already has this to a small extent. You can sign other stuff like domain DNS entries or HTTP servers (by hosting a file).
- deleted 10y ago[deleted]
- UweSchmidt 10y ago"How do you distribute the one time pad " Well you hand it over to the person you want to communicate with when you see them? Obviously that doesn't work in many use cases, but in many other cases it does: many of the most important secrets are typically shared with people you already know and have met before, no?
- sdenton4 10y agoLike when I buy a new laptop from new egg, or contact Laura Poitras with a hot scoop...
- UweSchmidt 10y agoNo. But when you discuss the real secrets with a journalist or business partner in another country. Email communication with family members, business partners. Potentially web traffic with your company's or bank's website, why not.
- KMag 10y agoThat's exactly what the OP was talking about when s/he said "temporally shift your security".
- jerf 10y agoWhen did you meet Paul Graham and hand over to him the crypto material you are using on the HTTPS connection you are reading this on? The vast majority of encryption in the real world is between people who did not meet and exchange crypto info. (Note this is specifically about one-time pads. While I agree the Web of Trust has failed, it is one effort to circumvent the problem.)
- WorldMaker 10y agoIt is interesting this realization that Power Users have very similar User Experience problems in Key Management that Novice Users have, but of a different degree. It does maybe speak to a deep conceptual usability issue in the WoT model. Maybe the tough learning curve has always been a symptom of the thousand papercuts of the Knowledgeable/Power User case and it is time to question the model and look for alternatives. The Web of Trust is built on long term trust of objects that should be short term and plentiful and that does seem an inherent contradiction in terms. WoT "best practices" have always been that keys should never live that long (at most two to five years being an old received wisdom back when I was most actively exploring the WoT), but proper key signing involves lots of little contacts (or key signing "parties") that are slow to accumulate and should last a great deal of time, but are applied to a specific key. Power Users can get some continuity between keys when rotating them by signing new keys with old ones before they expire, if they can manage that key that long and are prescient enough to build and sign a new key. (I know I lost continuity with my most trusted WoT key by not managing it well enough and I'm certainly not alone there; there is a great deal of churn in the WoT and lot of it is expired.) So Power Users try for longer term keys with further risks and even larger key management issues and with those longer term keys they try to manage a coterie of smaller term keys exponentially increasing the number of key management issues. Keybase seems to be the best bet at a trust model that distinguishes active keys from long term trust (social trust), and might be a good answer if they solve "average user" user experience. Signal and WhatsApp and some of the other OTR-ish mobile apps with E2E encryption seem to have solved some of the "average user" user experience problems, but don't seem to have good long term trust models. Somewhere in the soup maybe someone will solve more of the chicken-and-egg hurdles and evolve something that works for everyone.
- dom0 10y ago> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. It's simply that any and all software for PGP utterly fails in the UX and functionality department when it comes to key management. Web of Trust implies such a glaringly obvious visual metaphor that I am truly in awe that not a single program works that way. Tabulations of keys are not a WoT, period. I don't verify keys one-by-one, that's bullshit. I get one good key that's part of a WoT, and then go from there, and can easily see from the web structure that other keys are good and what their relations are. None of that is accomplished by any PGP frontend. Instead I get stupid and unhelpful error messages ("no key available" - I just downloaded it!) and some of the most terrible crypto UI I've seen ("How much do you trust this key? [ ] Not at all [ ] A bit [ ] Fully [ ] Totally" - w-t-f). A technical criticism of PGP/GPG is of course also possible. The whole thing is a museum of early 1990s crypto, with default ciphers like CAST5 and messages not being authenticated - and even if the message is authenticated most parts of the PGP protocol are not, meaning that you got that big bunch of C code maintained by that one German guy over there that parses unauthenticated bytes that you shipped through half the internet with a big neon-red sticker on it saying "I'M PGP PLEASE TAMPER WITH ME".
- cabalamat 10y ago> I don't think the "WoT" is conceptually flawed, and frankly, the argument that "people of average intelligence" can't grasp the concept comes from a very high horse and is also untrue. I disagree. I have written email encryption software, and I find WoT complicated. In light of this recent article on HN https://news.ycombinator.com/item?id=13111768 https://news.ycombinator.com/item?id=13111768 I suggest you re-evaluate the level of ability of the average user.
- smhost 10y agoThe standard for adoptability isn't the average person at their peak hours of attention and focus. It's the drunk teenager at 2 in the morning fumbling around in the dark.
- JulianMorrison 10y agoI'm going with fundamentally flawed. Or perhaps more exactly, a solution for a non-problem. Things PGP can do: - Hide the contents of a message. But not the fact of a message nor who it's to. And it's only as hidden as a key that your recipient has to keep secret indefinitely. - Permanently be incriminating, since the message can be as easily opened a decade from now. - Prove you're you. Which is great for incriminating you. Also the proof is only good if your secret key is still secret, which probably isn't the case if you've been arrested. At that point, it's good for convincing people it's you when it's really the FBI. - Authenticate keys through a trust mechanism so sparsely populated that unless you're actually in a spy cell, the chances of having a valid trust path from A to B is astronomically small. - Distribute keys through what is really only slightly more sophisticated than a world-writable Dropbox.
- Nadya 10y ago1) Key rotation can solve the second part of this. 2) Key rotation solves this, but you lose the ability to read old messages yourself. If you don't have the keys anymore you can't view the message. 3) This isn't unique to PGP? Or do you have an alternative? Because plaintext is infinitely less secure in this regard. 4) Depends how you determine trust of a user. In an ideal world you'd be correct. But I trust the person I've known for nearly 6 years is them when I signed their key, though we've never met IRL. Very possible it isn't them but is also astronomically slim of a chance. Key rotation makes the WoT even more complicated and less trustworthy. That's a big problem.
- JulianMorrison 10y agoMissing the point a little bit on 4. Proving you're you is great if you're, say, Canonical distributing package updates to Ubuntu, where the adversary is malware distributors. But where your adversary is eg: the FBI, then it promotes a false sense of assurance, because it's actually really easy to spoof someone if you can arrest them and force them to give the key password.
- Nadya 10y ago
- mtgx 10y ago> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. Why not both? PGP is definitely flawed with its lack of perfect forward secrecy.
- KMag 10y agoPerfect forward secrecy requires interaction between the two parties. So, either you need to require both parties be online simultaneously for their first interaction, or you give up on E2E encryption, or you allow the first message to not have PFS. (After you've established two-way communication, you can use Signal's dual crypto ratchet mechanism to maintain perfect forward secrecy with offline operation.) Now, maybe that first message is the null message or just a simple low-secrecy "Hello" message, but you still need that extra initial round-trip message to establish PFS. Of course, you need to delete emails once sent and once read in order for PFS to be of much value. However, without PFS, there's really no such thing as a deleted email, just emails the FSB/NSA haven't yet rubber-hosed you for the keys yet.
- jamesgeck0 10y ago> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. Last time I tried to use PGP on Windows, the gpg4win setup application crashed repeatedly during installation, and I had to use a walkthrough with screenshots because I couldn't figure out how to sign messages in Thunderbird. Forget deep conceptual usability issues; there are tons of major surface level usability issues.
- the8472 10y agoIs there anything that enables key exchange via smartphones? Ideally it should be as easy as a meatbag handshake. Basically, if you can swap contacts via NFC then the pgp keys should go along with it. It may have some theoretical weaknesses such as the exchange being MITMable if the users don't verify something on their screens, but I think having many more edges in the graph would make up for it since you might already have an expectation for that key through friends-of-friends paths.
- ryukafalz 10y agoOpenKeychain does this, provided both users have it of course.
- NoGravitas 10y agoTo expand on this, OpenKeychain wants you to use the camera on your phone to scan a QR code on your friend's phone.
- tibbon 10y agoSo not really for iOS :/
- hackermailman 10y agohttps://www.cylab.cmu.edu/safeslinger/ https://www.cylab.cmu.edu/safeslinger/ does simple handshake exchange and works w/iOS/Android but unsure if still maintained
- alistproducer2 10y ago>we have a deep conceptual usability issue here. yes, yes we do. All this stuff seems easy if you have the curiosity so spend hours and hours reading dry documentation about how it works. This is to say nothing of actually getting your hands on the tech and inevitably having problems that require more hours of forum searchs, IRC, and other time drains. It's not that "regular" people are too stupid to do this, they just don't see the value proposition in it. Even when the privacy issue starts to negatively affect regular people (think Black Mirror "Nose Dive") many still won't be interested in the technology to do what I wrote about above. I spent a bit of time in the crypto community and immediately I realized there is a human resources problem. the communities, for the most part, have no one that understands or care about how to dumb the UX down enough to make the value prop work for regular people.
- curried_haskell 10y agoAnd it's not just regular people, it's developers, programmers. Most devs I know look at pgp and are totally capable of figuring it out, but what they say basically boils down to: ain't nobody got time for that
- Steeeve 10y ago> I wonder if pgp is fundamentally flawed, or we have a deep conceptual usability issue here. IMO, the idea, the model, and implementation are flawed. The idea that people care about a web of trust in general is bad. The model itself relies on the assumption that it's a popular piece of software that is used in the way it's intended. PGP itself is popular, but only for the fact that viable alternatives are thin. The software implementation is confusing to technical end users, and third party front ends are just as bad.
- loup-vaillant 10y ago> The idea that people care about a web of trust in general is bad. Well, the very question is kind of a type error: people don't know what a computer is in the first place. 1 in 4 can't use computer in any capacity, and 90% of the rest have zero knowledge of the underlying principles. They don't even know if they would care about a web of trust. In the mean time, the powers that be are building us a network of universal spying. Oh well.