5 ms·
The poor UX behind gpg dissuaded me (and likely many others) from using it. Love the tree layout that's used here... time to get back into gpg.
by kingo55 5y ago
The poor UX behind gpg dissuaded me (and likely many others) from using it. Love the tree layout that's used here... time to get back into gpg.
- JasonFruit 5y agoI really don't get this attitude, though I think it must be valid, since I seem to be almost alone in disagreement. I use plain old GPG for a lot of purposes, and I don't find its command-line usage difficult at all. Key management, encryption, decryption, signing — all of these operations are pretty straightforward. What specific tasks have you found difficult?
- deleted 5y ago[deleted]
- sneak 5y agoIt's very hard to simply encrypt a file to a given pubkey (due to the key trust model) compared to, for example, something like age (where it's just `age -r $PUBKEY`). You also have to set GNUPGHOME somewhere and import the key first, you can't easily do it statelessly without tracking mud into the filesystem first.
- KirillPanov 5y agoI agree that age is a huge improvement over PGP, and the rightful heir to its throne. However most people complaining about PGP's UI go on to explain that this is why you should use Telegram or WhatsApp. That line of reasoning is just bogus.
- creamytaco 5y agoHuge improvement? It doesn't even come close. It's yet another half-assed reimplementation of the easiest PGP features to reimplement. There is no web of trust, no smartcard support, not even signing. Which is why age has gone nowhere, and pretty much everyone keeps using PGP.
- yrro 5y agogpg has had a --recipient-file option for a while now... no need to import it.
- user3939382 5y agoI get requests from non-technical people in my life for how they can email sensitive files (to other non-technical users) in a way that is especially secure. My refrain: “Technically there is, but… (contemplates PGP for half a second)… it’s very complicated to setup.” Between email phishing attacks, Dropbox and everyone else on HIBP, I honestly don’t know what advice to give non-technical users besides put it on a USB drive and drop it off. I can think of security pitfalls with literally any other file transmission technology that is easily accessible to non-technical users. If anyone has a suggestion I’m all ears.
- cpach 5y agoSignal (on desktop or smartphone) or https://webwormhole.io/ https://webwormhole.io/
- throwaway45209 5y agoFor webwormhole.io, it's server is a weak spot: https://news.ycombinator.com/item?id=23024833 https://news.ycombinator.com/item?id=23024833
- cpach 5y agoGood point.
- cpach 5y agoSignal
- KirillPanov 5y ago(r)age https://news.ycombinator.com/item?id=21895671 https://news.ycombinator.com/item?id=21895671 https://github.com/str4d/rage https://github.com/str4d/rage
- upofadown 5y agoThe thing where you have to deal with raw keys? For non-technical people? * https://articles.59.ca/doku.php?id=pgpfan:agevspgp https://articles.59.ca/doku.php?id=pgpfan:agevspgp