3 ms·
This attitude of "either you really need the security, so make do with whatever inconvenient method is necessary, or just forget about it" is what keeps secure
by prance 10y ago
This attitude of "either you really need the security, so make do with whatever inconvenient method is necessary, or just forget about it" is what keeps secure methods out of the mainstream, and thereby from widespread usage. This in turn means that anyone actually using those methods is immediately suspicious. Carrying multiple devices at the airport, or is there a Tails on that USB stick? Let's interrogate!
Also the notion that only journalists/whistleblowers by today's definition need this level of security is wrong. Your "normal", politically active person of today may be the whistleblower of tomorrow. E.g. after a regime change, or just by voting some crazy people into government. I'm living in a country where bloggers are sometimes arrested because of some alleged nonsense. But even in the West, it's nowadays all too easy to just be labelled "terrorist".
So the only sensical way forward is to popularize secure communication methods so that they are normally used by everyday people (including "professionals") with their everyday systems. This increased user base would likely increase the demand to close the existing holes and insecurities of the rest of the system, thereby creating a market force in this direction. And for this purpose, I agree with the author that PGP is not the way forward.
- bubblethink 10y agoI don't have an answer to all your questions, but there will always be a fundamental conflict of interest between privacy & security (of the end user) and market forces. You can hope for more usable systems that are also secure. If you are put off by Tails or usb sticks and different devices, look at QubesOs. They also have a good approach to security, but even they are having a hard time finding hardware that meets their requirements. In the end, you, as an end-user, will have to pick your trade-offs.
- prance 10y agoMy point is that as long as I have to choose non-mainstream OSs for secure communication, the tradeoff will not be worth it for me. As will be the case for 99% of "normal" users (most of whom don't even know that they can install alternative OSs, let alone on a USB stick). Things like QubesOs (which I had to Google) are interesting, but I think the general failure of Linux to become a mainstream desktop OS alternative proves that the chances of something like that gaining any relevant degree of popularity are minimal. So yes I accept the risk that this will come back to me one day, because there's no other practical choice. Just as I decide to go out of the house and take part in normal life, even though there's a high chance of getting into a traffic accident one day.
- bubblethink 10y ago>Things like QubesOs (which I had to Google) are interesting, but I think the general failure of Linux to become a mainstream desktop OS alternative proves that the chances of something like that gaining any relevant degree of popularity are minimal. Their chances of success are anyone's guess, but it does offer you the ability to run windows in a VM alongside other OSes. I don't know how good the windows support is, or whether it's even a priority for them, but that is probably the best tradeoff that you can hope for in a system that lets you run windows and still be secure (assuming the user doesn't go out of the way to break the isolation between VMs)