4 ms·
I found their “Out of scope” list very interesting. In particular, they list signing and “anything to do with emails” as non-goals. From my fairly limited under
by gpanders 7y ago
I found their “Out of scope” list very interesting. In particular, they list signing and “anything to do with emails” as non-goals. From my fairly limited understanding of cryptography, isn’t signing almost identical to encrypting (at least with RSA)? I don’t understand why this would not be supported in a self-styled PGP replacement.
I also don’t understand the “anything to do with email” line. Sending my public key to a recipient on an out-of-band channel and then sending an encrypted email should be completely agnostic to the underlying encryption tools, no?
I don’t mean to sound critical - I’m very intrigued by this project and would love to have a better replacement for gpg!
- wolf550e 7y agoPlease read this to stop thinking signing and encryption are related: https://security.stackexchange.com/a/87373/70830 https://security.stackexchange.com/a/87373/70830
- tinco 7y agoThey are related in the sense that encryption and signing algorithms use the same cryptographic operations. But the algorithms themselves are different, so having knowledge or faith in a certain encryption algorithm does not mean you have either in a related signing algorithm. They are separate domains.
- wolf550e 7y ago> They are related in the sense that encryption and signing algorithms use the same cryptographic operations. What is being encrypted in ECDSA? Or in Ed25519? You are wrong. Read the link.
- dependenttypes 7y agotinco did not claim that anything is being encrypted in ECDSA nor in Ed25519.
- wolf550e 7y agoI reacted to "isn’t signing almost identical to encrypting" and "encryption and signing algorithms use the same cryptographic operations".
- AgentME 7y agoAge is trying to avoid being an infinitely-flexible swiss army knife like GPG. It's been argued that GPG's do-everything design is the root of many problems both technically and in usability: https://latacora.micro.blog/2019/07/16/the-pgp-problem.html https://latacora.micro.blog/2019/07/16/the-pgp-problem.html. Minisign is a good similarly-small tool for doing signatures + verification of signatures and nothing else. The cryptography is similar, but the use-cases are often different. The tools both follow the UNIX philosophy of trying to do one thing well. Blenders and belt sanders both operate with motors, but no one tries to combine them into one tool. >I also don’t understand the “anything to do with email” line. Sending my public key to a recipient on an out-of-band channel and then sending an encrypted email should be completely agnostic to the underlying encryption tools, no? Yes, you can do that. Age doesn't want to involve web-of-trust, keyservers, key rotation, forward secrecy, post-compromise security, message repudiation, signing, email standards, and email client integration. All of these would be necessary for a good end-to-end encrypted messaging system. Try reading about the Signal protocol to see everything it does, and then try to figure out how to stuff it all into existing email systems. It's hard enough to get any of that stuff right even without the restriction of working inside email.