3 ms·
I agree about Signal for sure, actually I love it. Double Ratchet is especially intriguing to me as forward-secrecy is something that's often overlooked, as wel
by dacodanelson 8y ago
I agree about Signal for sure, actually I love it. Double Ratchet is especially intriguing to me as forward-secrecy is something that's often overlooked, as well as "exploding' messages. My only problem with Signal is that while it's nice to have a more reliably verified endpoint like a phone number for many contacts, it can't be used for communication between random people very easily. If I want to start an encrypted conversation with someone online I don't have to distrust them in order to be uncomfortable sharing my phone number with them. I get enough spam calls as it is, not to mention maybe I don't want this other person to be able to pay $10 or whatever it costs these days to reverse trace my number. It'd be great if there could be an ephemeral key you could generate for your profile for each new conversation you didn't want to have with someone that shares your phone number. That's really my only gripe with Signal.
However, Signal also is only for one thing essentially: chat. If I want to communicate via email or even just sign this message to verify it's me, I can't request Signal perform a signing function and generate some output so that others can verify I sent this precise message. Well, at least they can't verify that someone who claims in their public key declaration to be me didn't send this precise, unaltered message, haha.
Regarding linking identities together I agree entirely. I suppose in theory you could add subkey identities to your public PGP identity and then push those to keyservers. Something like [MyProfileName]@[ServiceDomain].[ServiceDomainTLD].Service or something (where it's not a real email address or domain) but it signifies that you're claiming that specific username at that specific service and then manually posting a verifiable proof publicly on that service. The only downsides there are that revocation is ... yeah. And everyone would have to agree on a standard for how to name identities for subkeys for services and that's honestly never going to happen.
Keybase messaging is pretty cool, I just wish it could be run from the terminal because I'm with you on the UI. Like chat history would still be in the GUI for review and stuff but you could spin up "keybase chat [username]" or something in a terminal and that just runs and let's you chat IRC style or something.
Surprisingly though I've found that teaching people how to use GnuPG for Mac is remarkably easy because it's well integrated with Mail and things like that. With Time Machine people really don't even have to migrate their keys properly. Only downside is that if someone loses their private key they'll have no idea what to do about it and again, revocation. The upshot though is that if they're using GnuPG you get, at very least, signed emails and then you're not outsourcing your identity to a third party like Keybase. I trust Keybase more or less ultimately because I can't see any reason for them to do anything annoying and they've got a great track record but trust is always violable.