4 ms·
> A bullet proof HOWTO can fix all of this You cannot document your way out of a usability nightmare.
by donaldstufft 3y ago
> A bullet proof HOWTO can fix all of this
You cannot document your way out of a usability nightmare.
- prepend 3y agoThe “usability nightmare” isn’t PGP/GPG fault, it’s PKI. PKI is hard to use because of its decentralized and free nature. The “fix” is to channel everything through google, or a government, or some third party that makes it easy and usable, but removes the main benefits of security, transparency, and independence. I think the reason GPG is all we have and has been for 20+ years is because that’s as good as it gets and better than nothing. It lets people who know how to use it communicate securely. So you can document your way out of an impossible to communicate securely nightmare.
- donaldstufft 3y agoThere's not a singular thing at fault. Though there is nothing inherently free or decentralized about "PKI", and given your conflation of those concepts I suspect that you're not actually aware of where the lines are drawn from. Certainly the decentralized nature of PGP adds some challenges to good usability. However, a large number of the problems come from the PGP spec itself (some of which is defensible in a 20+ year old spec, but not in anything in a modern system) and from GPG's poor implementation.
- prepend 3y agoI mean a PKI that I want to use. I only want to use a free PKI so everyone has access to it. And I only want decentralized as that seems sustainable to me without focusing power in a central entity. I use private, centralized, rather expensive PKI every day to log in for professional work. I wouldn’t want everyone to use that. And I wouldn’t trust my work for private secrets. I am pretty interested in this topic and would love for something better. But I’ve also used GPG for a few decades now and am able to communicate with people I need to. It’s certainly hard to use, but it’s pretty good for privacy purposes. What do you suggest we use instead?