5 ms·
A "complete replacement" for GPG would be a dumb idea to begin with. You want a specific tool for each of these use-cases. Choose one from the list for each us
by CiPHPerCoder 5y ago
A "complete replacement" for GPG would be a dumb idea to begin with.
You want a specific tool for each of these use-cases. Choose one from the list for each use case.
1. Private messaging: Signal, WhatsApp, Cwtch
2. File encryption: age
3. Encrypted backups: age + a Reed-Solomon encoder for catching flipped bits
4. Digital signatures: minisign, signify, OpenSSH signatures
The problem with GPG (and with PGP in general) is it tried to do too many things. Complexity is the enemy of security.
- upofadown 5y ago>Encrypted backups: age + a Reed-Solomon encoder for catching flipped bits I fear that I might of caused this idea. I have as a result added the following footnote to the article that I suspect is the cause[1]: >Please note that the single flipped bit here is not a realistic example and that in practice damage tends to encompass one or more media blocks. Such blocks tend to be multiples of 512 bytes. I am afraid that someone might actually implement this... [1] https://articles.59.ca/doku.php?id=pgpfan:agevspgp https://articles.59.ca/doku.php?id=pgpfan:agevspgp
- CiPHPerCoder 5y agoI don't read your wiki, so no, you were not the cause of it. This list item was prompted by a private discussion with friends.
- miles 5y ago> 1. Private messaging: Signal, WhatsApp, Cwtch WhatsApp’s record over the last decade does not inspire confidence, and the issues raised this year alone are quite serious: https://wikipedia.org/wiki/Reception_and_criticism_of_WhatsApp_security_and_privacy_features https://wikipedia.org/wiki/Reception_and_criticism_of_WhatsA...
- CiPHPerCoder 5y agoIt still uses better encryption than Telegram, Threema, and several other products that market themselves as "private messaging" apps.
- tptacek 5y agoSo don't use WhatsApp. That's a reasonable decision to make! I don't ever opt into it or recommend it to people (though I'd happily use it in preference to PGP email, which is doubtlessly the most risky secure messaging implementation on the Internet, arguably even more dangerous than simply using ordinary plaintext email with Google Mail).
- adament 5y agoThank you! I was unfamiliar with both age and Cwtch. From what I can tell, Cwtch is also a linear messaging system. Are you aware of any software offering secure non-linear (hopefully threaded) messaging, i.e. a secure e-mail replacement? It does not have to be MIME, SMTP, IMAP based like PGP, but preferably support for similar branching conversations and archiving and hopefully with support for multiple users. I love Signal but I find that finding old messages, or groups with more than a few people and branching conversations is a lot less pleasant than e-mail. And thus Signal is not currently a replacement for e-mail for me but a great addition.
- jolmg 5y agoIt didn't try to do what you put on that list. It didn't do messaging; messaging programs used it. It didn't do backups; backup programs used it. It's just a foundation-sort of program that does encryption and signing of arbitrary data, using one format for keys, and allowing working with those keys whether they're in the same computer or in a smartcard/hsm. That simplifies key management, since it allows you to have one Yubikey with your PGP key on it and do basically anything crypto related. But what I believe someguydave was referring to was stuff like smartcard/Yubikey support, not different uses of encryption and signing.
- CiPHPerCoder 5y ago> But what I believe someguydave was referring to was stuff like smartcard/Yubikey support, not different uses of encryption and signing. https://twitter.com/FiloSottile/status/1474941666545086465 https://twitter.com/FiloSottile/status/1474941666545086465 ¯\_(ツ)_/¯
- jolmg 5y agoage can't sign, though. It's not as useful. You can't use it for authentication, for instance. You need a separate program with a separate key and its own separate yubikey support.
- CiPHPerCoder 5y agoThis is a good thing. Separate tool for separate use cases. Bug jedisct1 if you want YubiKey support for minisign.
- jolmg 5y agoI'm fine with PGP, thanks.
- CiPHPerCoder 5y agoEnjoy your vulnerabilities