4 ms·
I think it's an excellent standard and its widespread adoption demonstrates this. Can you explain why you think it isn't?
by ifmpx 6y ago
I think it's an excellent standard and its widespread adoption demonstrates this.
Can you explain why you think it isn't?
- tptacek 6y agoIt has virtually no adoption. Every modern secure messenger application sends encrypts more messages, and between more pairs of people, than OpenPGP has in its entire lifetime. https://latacora.micro.blog/2019/07/16/the-pgp-problem.html https://latacora.micro.blog/2019/07/16/the-pgp-problem.html
- ifmpx 6y ago> It has virtually no adoption. The sheer volume of gpg-signed apt/rpm/tar packages downloaded and verified everyday cast doubt on your claim. I bet the number of packages downloaded for CI alone would invalidate this claim.
- tptacek 6y agoThey would not; you're either drastically underestimating the number of messages modern secure messengers handle, or overestimating the number of packages verified every day. But PGP is also an archaic way to sign packages, and there is no network effect to package signature schemes; all of them can, and should, be replaced with modern schemes like minisign/signify.
- ifmpx 6y agoOur disagreement here is on your claim that PGP has virtually no adoption. I brought up the monstrous amount of packages that get verified by CI/containers/OSs as an example where PGP is widely adopted. No one is claiming that dedicated tools can't do the job better. People use PGP because it is standard, widely-adopted, and does what people need it to do. From where I'm standing, people who argue against these three facts are underestimating PGP or overestimating their own favored solutions.
- tptacek 6y agoNo, people use PGP because at the times these systems were designed, there weren't better options; in some cases, there literally wasn't materially better cryptography, and in others, the better cryptography wasn't suitably enabled by good libraries. None of that is true anymore, nobody should be using the archaic PGP format for anything new, and, in most cases, people should be investigating how to replace PGP with modern alternatives.
- ifmpx 6y agoThis discussion was about your false assertion that PGP "has virtually no adoption". If you want to change our discussion to be about replacing PGP instead, then I completely agree that people should replace PGP with modern properly-standardized alternatives if such exist.
- pvg 6y agoFundamentally, the discussion is about your (and others') claims that PGP is some key part of security infrastructure and that its wide adoption and importance in such infrastructure shows that. It probably got a little stuck on broad terms like 'adoption' and 'standard' instead of looking more specifically at the type of use you're holding up as an example. Here's what happens in the super-common, basic case of 'installing a third party (i.e. not from the distro repos) package on some debiansy Linux': You access the the developer's webpage (via a browser and https) and read the installation instructions. They tell you to curl in (over https) some pgp key and some (https) endpoints for finding and downloading the package. You apt-whatever and the package is installed. The PGP part of this can be replaced with NOPs and this is no less secure. All the heavy lifting here is done elsewhere using infrastructure that actually has wide adoption and standardization and does useful things.
- ifmpx 6y ago> You access the the developer's webpage (via a browser and https) and read the installation instructions. They tell you to curl in (over https) some pgp key and some (https) endpoints for finding and downloading the package. > The PGP part of this can be replaced with NOPs and this is no less secure. That's one of most absurd hyperbolic assertion I've had the misfortune to come across in the whole PGP debate so far. You're clearly not acquainted well-enough with how PGP is being used by linux distributions. That, or you're simply debating this subject in bad faith. Assuming the former: HTTPS is only relied upon to bootstrap keys, like pretty much every other PGP replacement you're willing to advocate for. I know this may be painful to read for someone working on a PGP competitor, but PGP * is a standard, * is successful, * is widely adopted, and * will likely remain so for the foreseeable future. The op and the myriad of new PGP libraries and applications that keep popping up stand testament to this. You'd probably do better to reflect on this fact than to argue and downvote a green account on an old hn thread. Cheers.
- upofadown 6y agoThat article was actually the motivation behind my serious of PGP fan articles. I wondered what the opposite would look like, completely partisan, rabidly pro-PGP: * https://articles.59.ca/doku.php?id=pgpfan:index https://articles.59.ca/doku.php?id=pgpfan:index It turned out that PGP is not all that bad...
- pvg 6y agoIt's impressive as a character study of 'PGP Fan', it's not much of a technical rebuttal of critiques of PGP.
- aborsy 6y agoMessaging and email are different applications. People use messaging apps because of the rise of the mobile devices, not because these messaging apps use forward secrecy or ECC. Don’t try to link that adoption to crypto protocols! Also, very few of these users actually use secure versions such as signal or wire. They all happily post on Facebook‘s messenger and WhatsApp and don’t care about crypto.
- tptacek 6y agoMessaging applications use protocols derived from Signal Protocol rather than PGP because they had the opportunity to do something better than PGP. The first secure messengers did use PGP; designing a new messenger based on PGP would be malpractice. WhatsApp uses Signal Protocol, and protects many order of magnitude more messages every day --- or, if you like, bytes of plaintext --- than PGP ever has or will. Email not being a messaging protocol is... a take.