7 ms·
Can we stop with PGP please? It has served its purpose.
by whoisthisfor 7y ago
Can we stop with PGP please? It has served its purpose.
- kevinvdburgt 7y agoAny good alternatives?
- Avamander 7y agoStandard S/MIME for e-mail, minisign for signing software, standard ASICE for encrypted containers
- tptacek 7y agoS/MIME is even worse than PGP.
- Avamander 7y agoS/MIME has better e-mail client support and has massive deployment (use, not that much) in Estonia. I think it already beats PGP in two major aspects with that.
- tptacek 7y agoS/MIME manages the feat of being even less secure than PGP-encrypted email, which was, again, a low bar to trip over.
- Avamander 7y agoPlease elaborate.
- wolf550e 7y agoI think efail showed S/MIME was even more susceptible.
- Avamander 7y agoThat vulnerability has been largely mitigated, hasn't it? I'm really curious how GPG is more secure than S/MIME right now.
- wolf550e 7y ago"8.2 Countering malleability gadget attacks" in the efail paper says: "The S/MIME standard does not provide any effective security measures countering our attacks" and "Although CMS defines an AuthenticatedData type [29], S/MIME’s current specification does not." If the S/MIME spec does not enforce (and it seems it doesn't even allow, not just does't enforce) Authenticated Encryption, then it violates "the cryptographic doom principle" and should not be used for anything except CTFs and cryptopals exercises.
- Avamander 7y agoThe effective measure against their attack is signing and encrypting your e-mail sent with S/MIME? If it's just encrypted then yes, there's malleability issues but if it's signed I don't see it happening.
- yrro 7y agoNever heard of ASCIE, I assume you're referring to https://en.wikipedia.org/wiki/Associated_Signature_Containers#ASiC_Extended_(ASiC-E) https://en.wikipedia.org/wiki/Associated_Signature_Container...
- Avamander 7y agoIndeed. It's an EU standard, http://www.etsi.org/deliver/etsi_en/319100_319199/31916201/01.01.01_60/en_31916201v010101p.pdf http://www.etsi.org/deliver/etsi_en/319100_319199/31916201/0...
- rwbhn 7y agohttps://news.ycombinator.com/item?id=19173326 https://news.ycombinator.com/item?id=19173326
- ahazred8ta 7y ago"Things that use Ed25519" https://ianix.com/pub/ed25519-deployment.html#ed25519-software https://ianix.com/pub/ed25519-deployment.html#ed25519-softwa... is a grab-bag of nacl-style modern alternatives (of varying quality)
- jason0597 7y agoHow are we going to sign files then?
- tptacek 7y agoWith signify/minisign.
- jason0597 7y agoHow much market penetration do those have? Are they staples in the *nix world?
- mcpherrinm 7y agoIt's used in OpenBSD primarily. But it's a good tool and should get wider adoption.
- drenvuk 7y agoNo. Pgp still has a purpose to serve. Don't just parrot what other people say we should do with pgp. Just because it has some flaws doesn't mean all of the benefits it provides are rendered null. If you work around its flaws pgp has great assortment of utilities thay work beautifully.
- tptacek 7y agoIt does not in fact serve any real purpose, at least not in new systems --- or rather, the very few purposes that it exclusively serves are bad purposes. For encrypting backups, sending secure messages, signing packages, and securely sending files to people, there are materially better options. None of them look like PGP; that is, none of them have a multipurpose-tool design with a wide variety of cryptographic options. That PGP-style design has been discredited in the crypto engineering community, and new tools actively avoid it.
- madez 7y agoHow else do you recommend to independently establish a verifiable identity if not with PGP?
- asdvxgxasjab 7y agohttps://keybase.io/ https://keybase.io/
- deleted 7y ago[deleted]
- drenvuk 7y agoSo we should use a centralized service? The hell?
- akerl_ 7y agoIs there a functional web-of-trust for GPG? My understanding (and personal experience) is that if I want to message somebody using GPG, it’s super unlikely I can derive a pathway through the web-of-trust where I trust somebody who trusts somebody who trust somebody until we eventually get to my intended recipient. Even if that works, it banks of everybody in the chain having done a legit validation of identity, and there’s no way for me to know if they did (vs just picking a key off the web, signing it, and pushing that sig). And even if they did push that sig, where do I get the signatures from, given that the primary key servers used by GPG users are afflicted by a denial of service attack that was disclosed years ago? I’d bet that the majority of GPG usage involves checking the public key against the website of the other party (for example, against a fingerprint on a project’s site, or the person’s blog), and then maybe checking against another source posted by that person. Keybase is just some syntactic sugar around the “check the person’s sites for their fingerprint”. But I’d argue that if we’re going to just use that as a validating mechanism, we might as well just use minisign or Signal, depending on whether I’m validating package signatures or trying to send a message.
- stabbles 7y agoCan anyone explain why one would stop with PGP? This question presupposes everybody knows why, but I don't.
- tptacek 7y agoYou'll have to do some legwork, because discussions of PGP on HN quickly become unproductive; PGP has a very... "engaged" user subculture. A good Google search to start with is [matthew green PGP]. At this point, the serious discussion to have is less "what's a critical assessment of PGP" (dozens have been made over the last decade) but rather "for a given use case, what's the best alternative?"
- beagle3 7y agoAny standard I can replace PGP with, that has wide secure hardware element support? e.g. tptacek suggested signify which is awesome, but software only.
- ahazred8ta 7y ago"Howto: signify(1) signatures with a YubiHSM" https://marc.info/?l=openbsd-misc&m=155723329924761&w=2 https://marc.info/?l=openbsd-misc&m=155723329924761&w=2 https://ianix.com/pub/ed25519-deployment.html#ed25519-hardware https://ianix.com/pub/ed25519-deployment.html#ed25519-hardwa...
- kitotik 7y agofor users who use hardware tokens, what's the best alternative?