4 ms·
Then say that. Look, your article reads as a general attack on (encrypted) email. Independent of how it is implemented. You mention "PGP" 7 times: 5 times buri
by cipherboy 7y ago
Then say that.
Look, your article reads as a general attack on (encrypted) email. Independent of how it is implemented. You mention "PGP" 7 times: 5 times buried in the last paragraph of the intro, 1 time in a random paragraph on key rotation, and 1 time at the very end, as if your entire post was about PGP specifically. Hell, your title doesn't even mention PGP.
You mention "identity" 3 times, "metadata" 5 times, "keys" and "plaintext" 9 times each, "user" 11 times, "messages" 23 times, and the substring "encrypt" a whopping 41 times. IMO that "plaintext" and "PGP" are roughly equal in usage--and that "encrypt" dominates that!--says something far stronger. Here you're here saying "this post is about no PGP" and I'm saying "but you wrote no (encrypted) email".
I'm in agreement about PGP. I'd even go a step further and say you could say any encryption scheme on top of or underneath email would be weak. (Filippo's age? Jason's wireguare? $unicorn? etc.)
Why? Because of the concerns you enumerated in the post that are fundamental to the way the above RFCs work.
---
Think of the numbers and relative scales. x < 0.0001% of email users encrypt using PGP. and LARP. Fine. Attack those users in your blog posts and comments. But y >>> x of emails users play some part in replacing email in the grand scheme of things, with a more secure alternatives.
The expected impact of writing a blog post and convincing ~nobody to quit using PGP is much, much smaller than writing a block post and convincing someone to start consider building, investing in, or supporting others to build that replacement.
And IMO, you're 99% of the way to the latter, and 80% of the way to the former.
- tptacek 7y agoI can't say this any better than the article already does. If we replaced PGP with Age (a cryptosystem I like), email would still not be safe --- for all the reasons the article gives. This is not simply an argument about PGP.
- cipherboy 7y agotptacek: > This is not simply an argument about PGP. That's what I was just saying... Go reread it! But you also wrote: > My concern is that nerds are continuously trying to convince normal people that they should be encrypting email. That's dangerous, and wrong. I'm (just) trying to convince you to broaden the stated impact of your post. You're wanting table scraps from people who won't listen and who have no impact in turn. Ask for something bigger from people who might but have lots of impact when they do. You're nearly there.