10 ms·
OP has an extravagant threat model. Yeah if I were trying to hide communications from some dictator where even the metadata of recipient and timestamp is damnin
by begriffs 7y ago
OP has an extravagant threat model. Yeah if I were trying to hide communications from some dictator where even the metadata of recipient and timestamp is damning then of course email is out.
PGP is a good way to communicate under the right circumstances. Say I'm writing to someone I trust and have verified their key fingerprint via a secure channel (in person, over the phone, etc). If I were sending them login credentials for a shared site, or bank info for setting up a payment, or even just wanted to block general corporate snooping then what's wrong with PGP? It's "pretty good privacy."
It's nice that I can apply the cryptography on a local machine and then send the result over email. I don't need to sign up for the paranoid chat app du jour.
( In fact PGP is useful for more than signing/encrypting mail, see https://begriffs.com/posts/2016-11-05-advanced-intro-gnupg.html https://begriffs.com/posts/2016-11-05-advanced-intro-gnupg.h... )
- bad_user 7y agoHave you read the article? The problem isn't just the metadata leak, far from it. Some problems mentioned: 1. PGP is old and broken and messages can potentially be decrypted without access to private key 2. Because email's default is plain-text, in real world conversations you end up with people replying in plain text with your whole message being quoted 3. Archived messages will leak. An e2e channel needs to have a way to inform receivers that messages should be deleted after some time 4. Private keys eventually leak, therefore it is important that when it happens, the system makes it hard to decrypt old messages (by combining it with ephemeral keys). So if you have login credentials to send to someone, if you value that info and I assume you do, otherwise you wouldn't use PGP, then this is precisely the use case that encrypted email is terrible for. PGP usage is also very user unfriendly so you’re not losing anything really,.
- angry_octet 7y agoPractically speaking using PGP (or any other design of the same type) doesn't work to preserve privacy due to the architeture of email. Pervasive use of TLS for clients (IMAPS, web clients) and SMTP (STARTTLS) has had a far greater practical impact on securing email. Let's Encrypt has helped in enabling that. I haven't seen a report on whether GMail warning when domains were not using TLS has had an impact, but it did for me, because I told my accountant he had to get it done or I would change accountants. GSuite actually lets you prevent sending cleartext, i.e. making MitM downgrade attacks cause fail secure, rather than fail open. https://support.google.com/a/answer/2520500?hl=en https://support.google.com/a/answer/2520500?hl=en
- fs2 7y ago"1. PGP is old and broken and messages can potentially be decrypted without access to private key" Absolute nonsense, PGP is perfectly safe. Blame the broken cowboy software implementations.
- DyslexicAtheist 7y agowell PGP still has a very useful role in bootstrapping private communication in an OpSec sense. practical scenario to safely pivot would be to create a plain text file with this content: "please do not reply to this email - if reply or don't stick to the following steps I must assume you're compromised and have to ignore all other attempts at contact for both of our safety. Please send instead a message on <ricocet/signal/wire/session> with this exact content <proof/hash> so I know it's you, my userid is <userid>. I expect a reply until <time in the very near future>" Then encrypt that (using cli not the mail user agent) and send without subject. If they deviate from the agreement, or if there is a long delay in comms immediately cease all contact. Should give you reasonable confidence about the authenticity of the message after the pivot. Certainly beats using whatsapp or gmail to pivot to secure comms. But as you said, I wouldn't use it for anything else, not because I don't trust myself but the moment you share a secret it is no longer a secret and you have to take its halflife into account.
- bloak 7y agoIf the login credentials are used within 24 hours by the intended recipient to log in and then change the password then perhaps it doesn't matter if the message is decrypted by an attacker six months later. So I can think of worse use cases.
- gwd 7y ago> PGP is old and broken and messages can potentially be decrypted without access to private key This would be a lot more effective / helpful / convincing with a reference. > Because email's default is plain-text, in real world conversations you end up with people replying in plain text with your whole message being quoted This is more about the UI of mixing "normal" email with encrypted email. If you can insist that everyone install Signal, you can insist that everyone install Enigmail or some other piece of software which refuses to reply to encrypted mail without also encrypting. > Archived messages will leak. The specific argument from OP was "Searchable archives are too useful to sacrifice". I have a hard time expressing how obviously self-contradictory this line of argument is. Insofar as people are unwilling to give up archives, they will be unwilling to give up email. Insofar as people are willing to have email deletion policies, this isn't an argument to get rid of email. He's advanced the premise that people will never give up archivable messaging. So who exactly is he expecting to influence with this diatribe? Anyone who is unwilling to give up archiveable messages is going to be unwilling to give up email, period. At which point it's just pointless ranting. If you believe that people want encrypted, archivable messaging, then you need to give them the best solution possible, not just tell them not to want it. > Private keys eventually leak, therefore it is important that when it happens, the system makes it hard to decrypt old messages (by combining it with ephemeral keys). So one of the arguments against using PGP is that it gives people a false sense of security; and that having "experts" using it will encourage people to send messages which "should not be sent at all." In the case of ephemeral keys, you're still trusting the other party to delete both the keys and the messages after the stipulated time. But what reason do you have to believe that the other party is actually doing that? It would be dead easy for someone to write a client which didn't delete the message or the ephemeral keys -- either on purpose (because having an archive is convenient) or by accident. Wouldn't it be better to just tell people, "You can never guarantee that anything you send won't one day be decrypted, no matter what method you use. Take that risk factor into account when sending any message"?
- GoblinSlayer 7y agoWhen the author talked about broken pgp, he referred to an earlier post: https://latacora.micro.blog/2019/07/16/the-pgp-problem.html https://latacora.micro.blog/2019/07/16/the-pgp-problem.html granted, it proposes some alternatives, not for email though.
- dependenttypes 7y ago> and messages can potentially be decrypted without access to private key This is about e-fail, right? As far as I know this has been migrated and it worked in the first place only because of html messages. In addition to that it was not really the fault of gpg but rather the fault of badly implemented programs (because they did not check the mdc tag). > Archived messages will leak This is a bold assumption > An e2e channel needs to have a way to inform receivers that messages should be deleted after some time Surely the sender could mention this in the message. > 4. Private keys eventually leak, therefore it is important that when it happens, the system makes it hard to decrypt old messages (by combining it with ephemeral keys). This is a big usability trade-off. I avoid using wire because it takes ages (as in hours) to decrypt messages if I have not used it for a while.
- lvh 7y agoIf a bug happens in more than a handful of implementations, there’s a good chance the protocol is to blame. Perfect examples of where this emphatically is the case is MDC (PGP and Telegram are the only two common protocols in use I can think of where you don’t get a real MAC) and JWT’s alg debacle. Both were obviously ridiculous, and both led to serious vulnerabilities in almost every implementation under the sun. Mind you: with efail, some tools were using GPG directly. GPG produced unauthenticated ciphertext. GPG is also the dominant implementation. If GPG itself does this obviously broken thing, how do you expect third party implementations to get it right?
- jgalt212 7y agoOP has recently endorsed, or failed to deride, WhatsApp for this exact same reason. > 3. Archived messages will leak. An e2e channel needs to have a way to inform receivers that messages should be deleted after some time
- baybal2 7y ago> 1. PGP is old and broken and messages can potentially be decrypted without access to private key GPG works. > 2. Because email's default is plain-text, in real world conversations you end up with people replying in plain text with your whole message being quoted Don't quote > 3. Archived messages will leak. An e2e channel needs to have a way to inform receivers that messages should be deleted after some time Don't archive > 4. Private keys eventually leak, therefore it is important that when it happens, the system makes it hard to decrypt old messages (by combining it with ephemeral keys). Delete them before they do. The "new wave" of encryption like on from the guy calling himself Moxi Marlinspike is the prime definition of an unproven technology. The screaming headline is because he wants to make noise, and get cred for his crowd. His argument: GnuPG — a proven, and well reviewed technology is broken because some minor bugs were found, despite the fundamental crypto behind it still being more sound than anything else. He then follows to say that a fundamentally less sound, complex unproven system, is a better alternative. And that even when the novel crypto messengers themselves are dogged with daily minor security bugs being found. If I met the man in person, I would've said some warm words to him.
- cwyers 7y agoYour messages are only as secure as the least careful person you correspond with.
- inetknght 7y agoThat will always be the case though
- thaumasiotes 7y agoBut that's true no matter what methods you use. When you send a message, you don't enjoy any security at all from the recipient. If they decide to leak your messages, your messages will leak. If the way they decide to do it is by being incompetent, your messages will still leak. Look at the HackerOne reward policy for Snapchat: https://hackerone.com/snapchat https://hackerone.com/snapchat Among many less notable findings that aren't considered security issues, you can see that "screenshot detection avoidance" is a non-qualifying "bug". It's not really a bug. It doesn't qualify for a reward because your messages cannot be secured against people who are supposed to read them. Security against the recipient is (or was; I don't know the current marketing) a major marketing point for Snapchat, but it's never been something they actually offer. How is "your messages are only as secure as the least careful person you correspond with" more of an argument against PGP than it is against Signal?
- fxtentacle 7y agoWhat you describe sounds more like using PGP independently of email. I mean you could just as well put your secret data into a password-protected zip file and send that using a variety of methods. But I do think op has a point that there are two groups of people using encrypted emails: 1. Nerds using it for fun where accidental de-encryption doesn't matter too much. 2. Non-technical people where decryption might be a life or death situation and so they imitate what the nerds do, because they don't know that the nerds willingly tolerate the decryption risk. Op is now arguing that group 1 should stop so that group 2 doesn't get misled.
- wolf550e 7y agoFYI, password protected zip is completely insecure. Use age, or magic wormhole.
- tinus_hn 7y agoThere are modern versions that are not completely insecure.
- frandroid 7y agoEither they are secure, or they are not.
- lvh 7y agoThat’s true, but they’re not widely supported, so you can’t count on them to communicate. It’s also really hard to know for laypeople if the result is safe or not, so it’s dangerous to train them to accept encrypted ZIPs. Plus, as long as you don’t care about compatibility, you’re probably better off with encrypted disk images (DMGs or LUKS), because they don’t have completely dominant unsafe implementations.
- zaarn 7y agoThe filesystem drivers in most linux distro's (and I'd argue Mac and Windows too) have never been under scrutiny for security bugs. I wouldn't trust an ext4 image I got from the internet unless it was signed and from a trusted source, that's worse than ZIP files.