3 ms·
You're right, long-term identity keys are bad. Long-term identity keys are not a concept mandated by PGP, they are a result of how people use PGP or how PGP is
by m3ta 10y ago
You're right, long-term identity keys are bad. Long-term identity keys are not a concept mandated by PGP, they are a result of how people use PGP or how PGP is implemented in a third party app.
No part of PGP requires you to use a key more than once. This phenomenon is a result of a consensus of people deciding on a terrible operations strategy over a long period of time.
Edit: this comes to mind https://gist.github.com/grugq/03167bed45e774551155 https://gist.github.com/grugq/03167bed45e774551155
- FiloSottile 10y agoAgreed, I link to that Gist exactly in the "Moving Forward" section ;)
- m3ta 10y agoI must have missed that. I don't understand what the point of your blog post is, in this case. You understand why PGP is needed and how it's important, how to use it correctly, etc, yet you "give up" on it because no one you know uses it correctly. Is that it? By the way, how are you going to send someone a 5GB file securely using Signal?
- anc84 10y agoEncrypted in any way, hosted anywhere safe, sending the passphrase via Signal, done.