3 ms·
Nope. Keybase supports GPG keys, but they haven't been used or generated by default for three years: https://keybase.io/blog/keybase-new-key-model https://keyba
by digitaLandscape 8y ago
Nope. Keybase supports GPG keys, but they haven't been used or generated by default for three years: https://keybase.io/blog/keybase-new-key-model https://keybase.io/blog/keybase-new-key-model
There's no real reason to use GPG. Make an arbitrary scheme on top of something like NaCl and you'll probably be safer.
- jkaplowitz 8y agoPlease, nobody who isn't a cryptographer (to be clear: I'm not one either) should be arbitrarily inventing schemes of combining cryptographic primitives and hoping they're secure in production use cases. We'd often be wrong in such hopes, regardless of how good the underlying primitives are. We should listen to the experts in that regard, and preferably use higher-level libraries written by the experts when performing common crypto operations. This stuff is easy to get wrong.
- tptacek 8y agoNacl was designed by cryptographers for exactly this problem.
- moosingin3space 8y agoAdditionally, NaCl/libsodium is actually designed as a misuse-resistant API to perform real-world tasks, unlike GPG, where the API is "call this binary and use its crappy out-of-band signaling mechanism to figure out if anything went wrong".
- pferde 8y agoThis is what bugs me most about GnuPG - there's no real API, just an executable program with sometimes unreliable output. I mean, there is the GPGME library which wraps the executable calls in a C API (plus few other language bindings on the side), but it doesn't handle all the features the executable offers, often leaving you with a mix of GPGME API calls and "manual" calls to the gpg executable. I'd welcome some full-fledged libgpg that would reliably implement gpg the executable's functionality, similar to e.g. libcurl vs. the curl executable.
- lmm 8y agoEveryone would welcome it, but no-one's putting their money behind it. I suspect one of the real reasons that Signal uses a proprietary protocol (or rather, one of the real reasons that Signal was able to attract funding and improvements to GPG have not) is that having a locked-in userbase makes it easier to persuade VCs that there's a potential profit to be had. Whereas improving GPG would benefit everyone, but there's a tragedy of the commons around it.
- computerfriend 8y agoThe Signal protocol isn't proprietary, though. But yes, you make a good point. Although I'm not sure how much VC funding Signal really attracts.
- tptacek 8y agoZero. It's grant-funded.
- computerfriend 8y agoYeah, I expressed that badly, but meant to imply that they might receive VC funding in the future. For the record, I'm a Signal user and advocate.
- tptacek 8y agoWhat VCs are you talking about? Signal isn't VC-funded. It's grant-funded.
- jkaplowitz 8y agoI'm glad it's a good library. I was responding especially to "Make an arbitrary scheme on top of" whatever underpinnings one might choose, good or bad. That's not something we amateurs should ad lib where security matters. We will undoubtedly have to integrate and access libraries like NaCl. But we should do so in keeping with best practices recommended by cryptographers (e.g. through NaCl's documentation), not by layering an arbitrary scheme on top.