5 ms·
This discussion was about your false assertion that PGP "has virtually no adoption". If you want to change our discussion to be about replacing PGP instead, th
by ifmpx 6y ago
This discussion was about your false assertion that PGP "has virtually no adoption".
If you want to change our discussion to be about replacing PGP instead, then I completely agree that people should replace PGP with modern properly-standardized alternatives if such exist.
- pvg 6y agoFundamentally, the discussion is about your (and others') claims that PGP is some key part of security infrastructure and that its wide adoption and importance in such infrastructure shows that. It probably got a little stuck on broad terms like 'adoption' and 'standard' instead of looking more specifically at the type of use you're holding up as an example. Here's what happens in the super-common, basic case of 'installing a third party (i.e. not from the distro repos) package on some debiansy Linux': You access the the developer's webpage (via a browser and https) and read the installation instructions. They tell you to curl in (over https) some pgp key and some (https) endpoints for finding and downloading the package. You apt-whatever and the package is installed. The PGP part of this can be replaced with NOPs and this is no less secure. All the heavy lifting here is done elsewhere using infrastructure that actually has wide adoption and standardization and does useful things.
- ifmpx 6y ago> You access the the developer's webpage (via a browser and https) and read the installation instructions. They tell you to curl in (over https) some pgp key and some (https) endpoints for finding and downloading the package. > The PGP part of this can be replaced with NOPs and this is no less secure. That's one of most absurd hyperbolic assertion I've had the misfortune to come across in the whole PGP debate so far. You're clearly not acquainted well-enough with how PGP is being used by linux distributions. That, or you're simply debating this subject in bad faith. Assuming the former: HTTPS is only relied upon to bootstrap keys, like pretty much every other PGP replacement you're willing to advocate for. I know this may be painful to read for someone working on a PGP competitor, but PGP * is a standard, * is successful, * is widely adopted, and * will likely remain so for the foreseeable future. The op and the myriad of new PGP libraries and applications that keep popping up stand testament to this. You'd probably do better to reflect on this fact than to argue and downvote a green account on an old hn thread. Cheers.
- pvg 6y agoI don't understand most of this comment but I suppose at least we've come to agree that you can replace PGP with anything (like a NOP) in this particular use case.
- tptacek 6y agoNobody in this thread is working on a PGP competitor, nor is it acceptable on HN to allege that people are commenting in bad faith the way you just did. Please revisit the guidelines. If your arguments were sound, you wouldn't need to resort to personal attacks. Shore them up.
- aborsy 6y agoIf a modern alternative existed, it would have been invented. Email is hard to secure for obvious reasons. The PGP itself is fine, even though it could be updated.