4 ms·
> So I get the impression GnuPG is considered obsolete by the security community. This is news to me, but I'm not in "the Security Community". I can't find any
by Slackwise 8y ago
> So I get the impression GnuPG is considered obsolete by the security community.
This is news to me, but I'm not in "the Security Community". I can't find anything that corroborates this. Why do you say that?
- extrapickles 8y agoThe underlying crypto is fine (provided you don’t pick the weak algorithms) and use it correctly. What makes it ‘obsolete’ is that it lets you do bad things, like encryption without signing, messages can be partially encrypted/signed, etc. There are too many settings/options that amount to “change this to reduce security for no other benefit”. The current ideal is software that is only capable of being secure no matter how you use it.
- tptacek 8y agoThe underlying crypto is not really "fine". For instance, compare the PGP MDC construction to a modern authenticated cryptosystem.
- extrapickles 8y agoWhat I meant was that the crypto primitives (the implementation of the math) is good enough for the application, the use/assembly of them (eg: the system) leaves much to be desired. This also only applies to the algorithms that are currently considered not weak.
- tptacek 8y agoI'm talking about constructions, which are part of "the math".
- sneak 8y agoThe PBKDFs for symmetric (secring at rest and gpg -c) are also terrible. I'd love to be able to donate a few thousand dollars to a bounty to get this fixed.
- jancsika 8y ago> The underlying crypto is fine (provided you don’t pick the weak algorithms) and use it correctly. What is the target audience for GPG?
- asveikau 8y agoI can think of some uses: * Some package managers use it to sign binary packages. (Think apt-get) * I personally use it in shell scripts to avoid storing some secrets in the clear on disk. (Use case similar to ssh-agent)
- jancsika 8y agoNeither of those classes of user has the expertise to avoid picking "the weak algorithms."
- asveikau 8y agoI more or less trust the maintainers of dpkg and similar can figure it out or have someone point it out to them. My own shell scripts are maybe more iffy, as I am not myself an expert, but my personal use doesn't see wide distribution.
- moosingin3space 8y agoUnfortunately, even the maintainers of dpkg/apt, who rely on GPG extensively, don't manage to plug all holes: https://blog.packagecloud.io/eng/2018/02/21/attacks-against-secure-apt-repositories/ https://blog.packagecloud.io/eng/2018/02/21/attacks-against-... Personally, I'm of the opinion that APIs should be as misuse-resistant as possible, and GPG is notoriously intransigent about actually acting as a well-designed API. Additionally, The Update Framework (TUF, https://theupdateframework.github.io/ https://theupdateframework.github.io/) prevents these issues by design.
- asveikau 8y agoThanks for that. I know that Debian has had security blunders in the past (RNG problems anyone?) so as I typed it I had some hunches, but... Importantly though, it's a big project which in this specific instance meant that someone on earth did end up scrutinizing and publishing exactly the sort of thing you linked.
- sneak 8y ago> The underlying crypto is fine (provided you don’t pick the weak algorithms) That means it's not fine. Footguns mean it's a non-starter. Also, you don't get to pick the algorithms when you're the recipient of the message.
- nothrabannosir 8y agoThomas Ptacek, who is in the security community, expatiates on this in a sibling thread. It’s a good read, and I think it answers your question , which I didn’t know I shared :) https://news.ycombinator.com/item?id=18017982 https://news.ycombinator.com/item?id=18017982
- nickpsecurity 8y agoIt's considered obsolete by the mainstream security community. Their prior recommendations often got hacked a lot, too. There's a niche group that promotes stuff that is stronger even if there's drawbacks to using it. We also let people decide if they accept those drawbacks. I'm in that crowd. I noted that the Snowden leaks said the NSA of all groups hated GPG since it blacked out their collection efforts. They had to send their limited team of hackers to deal with people doing that hitting other parts of their systems. If NSA isn't regularly breaking it, then it should be strong enough to stop all the threats likely to bother me. I push it plus a limited set of commands that make it easy, but annoying, to use. Instead of email, I just tell people to encrypt/sign text and zip files with boring names. That lets us dodge vulnerabilities that come from metadata, email interactions, and so on. Then, send them via whatever mechanism ranging from convenience to full anonymity. Truth is I rarely use it because other people rarely communicate to me encrypted or request it. They usually send stuff to my Gmail account in plaintext or HTML. It's there if I need something stronger. It's a pain in the butt. I at least know it has a stronger baseline than most tools which are unknowns to me that I assume will get hacked until seeing evidence otherwise.