3 ms·
I have been using OpenPGP for years without problems. Key transition / exchange / verification can be a bit painful, but actually it is not that hard. Also the
by sleepless 10y ago
I have been using OpenPGP for years without problems. Key transition / exchange / verification can be a bit painful, but actually it is not that hard.
Also the longer you use OpenPGP, the less keys need to be verified. The start is very hard, since you start with no trusted keys at all. The longer you use it, the more fluent usage becomes.
Have been using GPG Suite on macOS and the only problem is, you may not get support for the new macOS on day 1 since apple provides no API for Mail.app. And then again, giving Apple some time to figure out their bugs of the intial major release isn't a bad idea.
- FiloSottile 10y ago> Also the longer you use OpenPGP, the less keys need to be verified. The start is very hard, since you start with no trusted keys at all. The longer you use it, the more fluent usage becomes. This is exactly what scares me and the point of my "I'm giving up on PGP" article. People holding on to keys forever, moving them from laptop to laptop, never rotating them and asymptotically approaching compromise... because it's the only way to ease the pain.
- peatmoss 10y agoHow do you feel about Yubikey-based keys? Asking for a friend...
- subway 10y agoMost workflows utilizing OpenPGP cards (like the Yubikey) encourage better key hygiene. Generally you'd create a certification key which lives offline 100% of the time, with a subkey issued to the Yubikey. This means your offline key can persist for a very long time while you can safely rotate the day to day subkey. Unfortunately while these workflows are encouraged, the tooling doesn't exist to make it a trivial operation for folks not familiar with proper key hygiene.
- matheusmoreira 10y agoI have a YubiKey myself and they're really convenient. There's a cryptoprocessor inside so the key doesn't have to leave the device. I think it's more secure than a regular computer connected to the internet. After reading¹² about this subject, I believe a reasonable level of security and ease-of-use can be achieved through the following process: 1. Boot a live Linux distribution such as Tails on a computer disconnected from the Internet. 2. Create the OpenPGP master key. 3. Initialize the YubiKey with subkeys. 4. Store the master key offline using paperkey³ and a machine-readable code. The YubiKey is secure and convenient enough for daily use; the subkeys can be easily revoked and the hardware reinitialized with new keys. Master key operations such as key signing and changing expiration dates require loading the master key into the offline live operating system. Much more of a hassle but hopefully not as frequent as YubiKey use. Printing the master key on quality paper ensures³ it will survive for a long time. ¹ http://security.stackexchange.com/a/51776/9252 http://security.stackexchange.com/a/51776/9252 ² http://security.stackexchange.com/a/31598/9252 http://security.stackexchange.com/a/31598/9252 ³ http://www.jabberwocky.com/software/paperkey/ http://www.jabberwocky.com/software/paperkey/
- sleepless 10y agoWhat would you consider a sane key rotation cycle? 1 Month? 1 year, 2 years, 4 years?
- jandrese 10y agoYou gloss over the key management, but it is the primary failing of PGP (and GPG). The lack of built-in key management means it is only half of the solution, and the community has never managed to coalesce around a single sane solution. Instead we have people trading paper notes or using grotty services with custom protocols and if you just want to send an encrypted email to somebody there's no standard way to look up their key. I have yet to find an email client that will even do the simple search of the keystores for you. It's maddening.