12 ms·
PGP needs to be retired in honor
- it3mz 10y agothen what to use? provide alternative.
- falcolas 10y agoPerhaps I'm just out of touch, but I'm not familiar with any of the alternative tools they mentioned. If we retire PGP (and its GNU clone), what widely available tool should we use in its stead?
- gregoryrueda 10y agoSignal? Some paid services seem to be blossoming, see https://protonmail.com https://protonmail.com
- datatan 10y agoProtonmail uses PGP............
- falcolas 10y agoSignal is not much of a PGP replacement. There's a lot that PGP can do that Signal can't: signing, encryption of large blobs at rest, and key management. I use PGP as part of my backup solution, encrypting my backups at rest with an asymmetric key. I can't do that with Signal.
- tptacek 10y agoSignal does a better job of practically everything PGP does with regards to message encryption. Yes, PGP is more useful for encrypting files or signing updates. I agree that it's too early to write of PGP for those applications. But people should use Signal instead of PGP for message encryption.
- Tharkun 10y agoHow would that work? Last I checked, Signal used Signal servers for key exchange (or whatever the equivalent in their lingo is). Is there any way to use Signal without relying on their servers?
- nickpsecurity 10y ago"Signal does a better job of practically everything PGP does with regards to message encryption." Except for endpoint security. The ultra-portable, self-contained implementations of PGP can run on countless configurations of desktop or embedded system. Transport methods also vary if they're funning messages or files through other apps. All sorts of hardening or isolation techniques can be applied. Remote attackers have a lot to look at trying to break or bypass GPG for an arbitrary user. Whereas, vast majority of Signal use relies on one app with two OS's. The extra security tech and obfuscation you can layer on PGP/GPG is still an advantage in its favor until competition gets that.
- falcolas 10y ago> But people should use Signal instead of PGP for message encryption. I won't disagree; when your usecase is in Signal's wheelhouse, by all means, use it. But as someone who uses PGP regularly; the limit of how I could use Signal instead of PGP is limited to the occasional transfer of PII, passphrases, and private keys (something I couldn't use Signal for, since these are typically sent between GUI-less hosts). A very tiny fraction of my PGP usage.
- Freak_NL 10y ago> But people should use Signal instead of PGP for message encryption. Signal the protocol or Signal the service? There does not appear to be a mature FOSS toolchain for the former that can replace gnupg and Thunderbird/Enigmail, and the latter is only available on Android and IOS smartphones.
- tptacek 10y agoDon't use email to send secret messages.
- mstef 10y agoopmsg does masquerade as gnupg on the cli, if you take this further you could create a gnupg chameleon which detects what keys are available or what the input is based on auxillary info and then invoke the appropriate tool (which might be gnupg, or something else). on a different note: gnupg is not widely used, signal is.
- datatan 10y agoSignal is for text messaging and fails as an email replacement. It also does not work for signing code and it requires you give over your contacts list to a third party to work. Signal is not fit for PGP's use case.
- dublinben 10y agoSignal is actually quite sufficient as an email replacement. You can send media attachments, and even include several recipients. It is unquestionably a better encrypted messaging system than PGP.
- tapoxi 10y agoUnless you actually need to send email with Signal, or want to be anonymous, since Signal uses your phone number.
- mstef 10y agopgp does not provide anonymity at least not in the widely accepted form. every message has the recipient keyid in plaintext, unless you --throw-keyids but then you run into incompatibilities and inconveniences that make the whole exercise user unfriendly and widely unsupported.
- falcolas 10y ago> pgp does not provide anonymity Not quite true. > every message has the recipient keyid in plaintext The keys are not required to be centralized in any particular location. There is no way to tie a key to an individual, unless that individual wants to be associated with that key id. It's common practice to post anonymous, encrypted messages on mailing lists or newsgroups. All you can really tell in those cases is that the recipient is a member of that mailing list or subscribes to the newsgroup (though it's not for sure, with the use of remailers, etc).
- skrowl 10y agoQuite a few listed here - https://alternativeto.net/software/gnupg/ https://alternativeto.net/software/gnupg/
- tptacek 10y agoThis is an unvetted list of random programs that claim to perform this- or that- cryptographic operation; it's not really helpful.
- twothamendment 10y agoThere are quite a few things listed there, but I fail to see one that looks like a replacement for PGP. Many are some form of PGP compatible encryption - some different platforms Android(AGP), Windows(GPG4Win, Fort) Apple(GPG Suite for apple mail). Some will only encrypt files with a password, others encrypt your disk. There might be some good software there, but I don't see anything that can replace PGP/GnuPG. Using PGP/GnuPG isn't always easy, but it works for so many things. Signing code, encrypting files, emails, signing messages - replacing it is a fairly high bar. I'd love to see encryption easy and used everywhere, but a few popular apps don't add up to replacing this old work horse.
- mstef 10y agocheck out opmsg how it achieves compatibility with gnupg and imagine a tool that actually looks like gpg but figures out which crypto backend to call.
- falcolas 10y agoInteresting project, but I'd personally want to see a lot more involvement and vetting from the crypto community at large. Especially when it creates new protocols like DH key exchange over email.
- drzaiusapelord 10y ago>but I'm not familiar with any of the alternative tools they mentioned. The tinfoil hat part of me has been seeing this push for the Signal protocol straight out of nowhere and am a little worried its being done by a state level actor who knows something about it that we don't. Its much younger than PGP and as such has had less eyes on it. I also don't think Moxie Marlinspike, the founder of Signal's owner - Open Whisper, has the cred and trust Phil Zimmerman had, at least not yet. Its particularly worrisome as he seemingly is only known by a pseudonym. I also would consier S/MIME, which is baked into most feature-heavy email clients including iOS, a practical alternative to PGP when the use case is email encryption. You and a friend can get certs easily, put them in your client via GUI, and be done with it. No command line skills needed if ease of use is the big complaint here. For the less technically inclined its a pretty good solution, pun intended.
- mstef 10y agoif you knew the story you'd know that Phil did actually an abysmal implementation which had to fixed by others.
- drzaiusapelord 10y agoI think I've read about Phil's shortcomings, but in the end he made it happen both technically and politically. I'm ok with software being a community effort and the less talented being helped by the more. Its a group effort to me and I don't believe in the coder superman mythos is required for good software. Not everyone can be a Linus or a Carmack.
- verytrivial 10y agoI think the title is a little inflammatory. The conclusion does not say we should stop using PGP but consider the weakness inherent in its operating model and assumptions when evaluating future replacement. I think it is fair to say that the world is still waiting for said replacement, and until that arrives, PGP still has a number of valuable properties, one of which being it exists.
- mstef 10y agothe listed examples all exist. signal is already more widely used than pgp ever was in the last 25 years.
- datatan 10y agoThats an impossible statement to prove. Signal is centralized with a concrete list of users. PGP is decentralized with no possible way of knowing how many use it or dont
- mstef 10y agocount the keys on the keyservers, apply some multiplier, chances are that it's still less than signal users today.
- OJFord 10y ago> PGP is decentralized with no possible way of knowing how many use it > ..., apply some multiplier, ... You glossed over that like it was nothing. Let me rephrase GP: "... with no possible way of knowing the multiplier". Obviously there exist k such that for n keys on "the keyservers" (we'll have fun enumerating those too) and s signal users, k*n > s.
- mstef 10y agoaccording to http://keys.mayfirst.org/pks/lookup?op=stats http://keys.mayfirst.org/pks/lookup?op=stats there's currently 4594571 keys on the bulk of public keyservers. considering the rumors that facebook and others also do signal and their user base is around a rumored billion, the k that i glossed over is around 217. even if we assume that there's dark masses that never ever used a keyserver, we ignore the fact that out of those 4.5 million pgp keys most are expired, revoked or simply lost, so the active keys on the keyservers are probably much less, and thus k is also much bigger.
- mc42 10y agoMy biggest point of contention with this is... what should replace it? PGP is the current and retroactive psuedo-standard for verification for everything from email to code to builds. Any replacement would have to be at least semi-compatible, so as not to break the (likely) hundreds of solutions relying on and expecting PGP.
- tptacek 10y agoThis is in fact the problem with trying to write eulogies for PGP. PGP is still a useful tool, just not for the application it was originally intended to: it's a very idea to try to retain secrecy among even small groups of people using PGP-encrypted email.
- jwilk 10y agoVery idea?
- thaumasiotes 10y agoContext suggests a typo for "very bad idea". Although I kind of like the image of tptacek thinking about using PGP for email and scoffing "Hmpf! The very idea!"
- verandaguy 10y agoI used to be skeptical about this... but if the Signal protocol sees more widespread adoption outside of the Signal app and Whatsapp, it could be a good fit. I'm very open to hearing about reasons why this wouldn't be the case, though.
- bubblethink 10y ago>"Consider your average investigative journalist or whistleblower, with windows or a mac, that they haven't updated because then their kids favorite game doesn't run anymore or they simply don't want windows 10. .... This makes forward secrecy a mandatory requirement, as this implies that the malware has to be constantly active and thus also enhances chances of detection and mitigation." This is a bit of a straw-man argument. Forward secrecy or not, if you can get root on the client device, you own everything. So if you are a journalist/whistleblower, and have invested the effort to learn PGP, you should use Tails or something more appropriate for your job than windows or a mac. Edit: This may be a good use case for hardware support for trusted execution (Intel SGX), along with all the other nasty features that it brings (DRM). The threat model for trusted execution is that the OS cannot be trusted whereas the app is sacrosanct.
- nemothekid 10y agoSo for those us that need to run Windows/OSX to run software, like Photoshop, for our job, we should just give up on PGP? Seems like a supporting argument for the article then.
- verytrivial 10y agoYour argument comes down to the threat model. A journalist whom also uses Photoshop is free to use whatever system they have sufficient trust in for the nature of the communication at hand. If they're likely to be killed because someone reads the content of their messages, they should easily be able to weigh that cost against needing to boot of USB every now and again. So that said, if you use crypto-system X on a machine you cannot trust, crypt-system X will not be able to protect you very much.
- nemothekid 10y agoI understand the threat model. However that notion implies that those of us who aren't at risk of death over our emails should give up PGP. Given that (I assume) most of us aren't at risk of murder by the nation-state, PGP is dead. I would prefer a solution where everyone could reasonably get end-to-end encrypted emails. Unfortunately, given the unfitness of PGP for this goal, coupled with recent work in the space, it looks like we will either get plaintext over decentrailzed email, or e2ee inside walled gardens.
- platz 10y ago> hopefully there'll be more and better tools Good criticism, but we need an actual plan for "repeal and replace", rather than "hope" for better tools.
- sildur 10y agoAgreed, PGP is dead, long live to GnuPG!
- dmix 10y agoGPG is still the domain of nerds. But yes, we all still use email and as long as we do I will use GPG with my coworkers who know how.
- nickpsecurity 10y agoOr people that value strong privacy + will tolerate using a command written down on a piece of paper.
- krick 10y agoI started reading to know what's wrong with PGP, but it very quickly escalated to the discussion about making educated bets about cryptography as a whole. I think this is hugely important topic and it is a real shame this is not being discussed more. Maybe security people a more conscious about that (I surely hope so), but general public doesn't seem to be. And by "general public" here I actually mean self proclaimed paranoids and not your grandma or a girlfriend. We talk a lot about if something is proclaimed secure by so-called experts, about theoretical weaknesses of Telegram or something, monitor important 0-days, buzz about how bad it is to give all your private data to facebook or google and how fucked we all are. But we rarely seriously talk about who our adversaries really are, what exactly we are trying to protect and if we're using the right tools for that. About making educated bets. And in the end of the day, this is all it is actually about — making educated bets. Because not all our data, not all our accounts are equally important, and they are not equally important to the different kinds of adversaries. So the only way to be somewhat secure is to recognize, that there's no absolute security and we cannot protect everything. So better start taking it consciously and focusing on what's really important.
- zobzu 10y agoAnother "I don't think PGP is good enough" and "here's all these things" Yet none fully replaces PGP yet. Before you actually retire PGP, maybe you need one of these projects to finish a real, complete, reviewed and high quality replacement ;-)
- mstef 10y agosome of these tools actually fully replace pgp (see opmsg for example) however that is actually a very low bar to master. it seems pgp is seen as a silver bullet handling all use-cases like a charm, this is far from reality, actually it fails in many cases, and specialized tools might actually fit the purpose much better, also surpassing pgp in their special niche.