3 ms·
I can agree with all the PGP bashing in the world, but it seems to me that PGP provides one thing that apparently nobody else cares about, and I don't understan
by giomasce 7y ago
I can agree with all the PGP bashing in the world, but it seems to me that PGP provides one thing that apparently nobody else cares about, and I don't understand why: the thing is identity verification. When I encrypt or sign I don't just do it for the sake of itself: I want to be sure to whom I am encrypting and from whom I am verifying a signature. If I am not sure of what is the link between the used key and an actual person, organization or service, crypto is not very useful for me. PGP has a way to do that. We can speak for hours of its pitfalls, but it's there, and with same care it can be used.
Do the alternatives have anything similar? I don't think so. Signal and WhatsApp basically rely on a GSM identity (a telephone number), which is verified by checking a six-digits code by SMS. There are hundreds of ways to screw this up. Any random street pickpocket would be able to get your phone, read the code and put it back in your pocket without you even noticing, not mentioning attack on the actual GSM protocol of which I do not know much (but have heard of its insecurity more than once). It's true that there is Perfect Forward Secrecy and your peers will get a little notice saying that your security code has changed (and will most probably ignore it), but if it is so easy to take over one's identity, I don't think I can put much trust if the system as a whole. (also, OP complains that GPG is a complex and obscure implementation; what are they going to say about GSM stacks?)
Ironically, the thing that would make this system secure would be that people actually checked security codes, which would basically amount to what PGP users do when they exchange fingerprints (and I am sure OP would consider that the LARPmost possible thing in the universe). Not even with the advantage of having a proper Web of Trust, though.
Even TLS, although it is not mentioned by OP, has quite a few problems. Most TLS certificates are Domain Validating, and the validation procedure essentially consists in recovering a secret file by mean of an HTTP request to that domain (surely that's true for Let's Encrypt, but I believe that most commercial DV operators work in the same way, except that you have to pay for it). So as soon as you're able to MITM the domain validation (and there are a lot of actors who are able to) you can grab the certificate, which would in theory protect from those who are able to MITM your server. This mechanism still protects your from MITMs positioned close to the client, that's true and it's better than nothing. But you still have all the holes you want. And bad examples of TLS CAs are nothing near missing.
So, bottom line: I am very happy if you give me modern and advanced tools for encrypting stuff, but please do not ignore the problem of giving names to keys, a problem that as far as I know only PGP is currently able to tackle.
- isodude 7y ago> So, bottom line: I am very happy if you give me modern and advanced tools for encrypting stuff, but please do not ignore the problem of giving names to keys, a problem that as far as I know only PGP is currently able to tackle. I think that SQRL (grc.com) gives us hope here. Focusing on making is easy for people in general to keep a secret signing device would be a big leap forward, since you can base other identity service on that. Add Matrix to that and you get identity as well.