6 ms·
PGP is bloated and complex, trying to be the Swiss Army Chainsaw of encryption and verification. It lacks modern features of encryption tools such as channel bi
by Seirdy 5y ago
PGP is bloated and complex, trying to be the Swiss Army Chainsaw of encryption and verification. It lacks modern features of encryption tools such as channel binding (which opens whole categories of exploits) and perfect forward secrecy (instead preferring to use long-lived keys, which are a nightmare of their own).
PGP also allows a host of insecure options without mandating secure ones: while it does offer good algos and distribution mechanisms (e.g. WKD), it also offers poor/deprecated algos and disasters like keyserver pools.
As for Signify: Minisign supports trusted and untrusted comments in signatures to supply metadata.
Some distributions like OpenBSD and Void Linux have finally upgraded their package signing from PGP to Signify; Debian is in the process of migrating from PGP to Ed25519 sigs (https://wiki.debian.org/Teams/Apt/Spec/AptSign https://wiki.debian.org/Teams/Apt/Spec/AptSign). If we manage to switch enough distros off PGP, maybe we can remove the need to have PGP installed by default.
- upofadown 5y ago>PGP is bloated and complex... Not in any relative sense. The commonly used Signal protocol for example is much more complex and is only applicable to one narrow category of application. In the Keyoxide case we are only doing signing so that is the only part of the OpenPGP standard that would be applicable. >...channel binding... Could you expand on how that might relate to PGP applications? >...perfect forward secrecy... ... is not relevant for the protection of things like files. Even for messaging it is rarely of any value as users like to keep their old messages around. >...poor/deprecated algos... See my other reply: * https://news.ycombinator.com/item?id=29138592 https://news.ycombinator.com/item?id=29138592 ...OpenBSD... OpenBSD needed something compatible with the license of the base distribution. The mistake made was that signify was not made to use a preexisting format. So it is an attempt to create a whole new standard in a way that provides no benefit to anyone.
- Seirdy 5y ago> In the Keyoxide case we are only doing signing so that is the only part of the OpenPGP standard that would be applicable. The problem is that PGP does a lot of stuff besides signing too; this is bad design, and is one in a long list of issues with PGP. Its network effect extends to areas where issues like the lack of channel binding and PFS are relevant (e.g. communication platforms): people use the "it's already installed (for something else)" argument far too often to justify using it for something it isn't suited for (most other things). > OpenBSD needed something compatible with the license of the base distribution. The mistake made was that signify was not made to use a preexisting format. So it is an attempt to create a whole new standard in a way that provides no benefit to anyone. Signify's standard is dead simple, and already has several implementations. The friction involved in adopting it is low enough for this to be a minor concern. The benefit is that it helps us move away from complex dependencies like GPG and towards simple ones like minisign/signify that only do what's necessary.
- georgyo 5y ago> PGP is bloated and complex, trying to be the Swiss Army Chainsaw of encryption and verification. It lacks modern features of encryption tools such as channel binding (which opens whole categories of exploits) and perfect forward secrecy (instead preferring to use long-lived keys, which are a nightmare of their own). Strong identity and long lived keys are a requirement. Perfect forward secrecy does not make sense in a world were I want to prove that all things signed by me are in fact signed by me. If I generated a new key, how do I distribute that key to someone else in a way they can trust that key? And if you have that secure channel working and trust worthy, why do you even need to sign anything? Even in the case of debian apt signing changes, all the key signing happens in the public view, there is nothing secret about it. Perfect forward secrecy is only for encryption and does not make sense in the case of signatures, but even in the case of encryption (age) you have a similar key distribution problem. If you are constantly making ephemeral keys that's great, but it also means you need the receiver to make a new key on every file the sender wants to send. This means people will still have long lived keys, and perfect forward secrecy does not apply. Lastly, in most async communication, like email, PFS is very difficult because you don't have channels that can easily negotiate channels. There is autocrypt which gets pretty far, but has it's own troubles. For any real time communication, TLS and Olm are the way to go. But at this point we are very very far away from minsign which. > PGP also allows a host of insecure options without mandating secure ones: while it does offer good algos and distribution mechanisms (e.g. WKD), it also offers poor/deprecated algos and disasters like keyserver pools. PGP has been around for a long long time. None of the options were insecure when they were implemented. Minsign and age have decided that their tools will only have 1 algo, the correct and most secure one. However that can change in just a few years. At which point it will either become more like PGP or we will have to migrate everyone to the new best tool. This is madness. A PGP implementation that was more aggressive at deprecating weak methods is far better than this new pointy tools. > As for Signify: Minisign supports trusted and untrusted comments in signatures to supply metadata. As you say this data is untrusted and unsigned. Having it proves nothing about the ownership of the private key. > Some distributions like OpenBSD and Void Linux have finally upgraded their package signing from PGP to Signify; Debian is in the process of migrating from PGP to Ed25519 sigs (https://wiki.debian.org/Teams/Apt/Spec/AptSign https://wiki.debian.org/Teams/Apt/Spec/AptSign). If we manage to switch enough distros off PGP, maybe we can remove the need to have PGP installed by default. I have read their reasoning on this several, and I firmly believe this is a huge mistake. Or at the very least a lot of work that provides no actual value. However the keys here are distributed by packages, so there is already a TOFU when you install the system. In the end there is not actual end user impact here, besides making it much more difficult to know if the signature of a package is valid manually.