4 ms·
I recently came along this post [0], which pretty much killed PGP for me. I certainly cannot follow all technical detail in the post, but I do see that cryptogr
by phkx 3y ago
I recently came along this post [0], which pretty much killed PGP for me. I certainly cannot follow all technical detail in the post, but I do see that cryptography has moved on and now offers e.g. forward secrecy.
[0] https://latacora.micro.blog/2019/07/16/the-pgp-problem.html https://latacora.micro.blog/2019/07/16/the-pgp-problem.html
- phkx 3y agoI should add that some of the risks mentioned in that post can be mitigated by proper user behavior (use a sufficient key length, limit the lifetime of your key). But then PGP is sufficiently complex and error prone (in using it and apparently in its technical complexity), that I don’t believe that it scales to everyone and their grandma using it.
- upofadown 3y agoI found the "The PGP Problem" fairly misleading: * https://articles.59.ca/doku.php?id=pgpfan:tpp https://articles.59.ca/doku.php?id=pgpfan:tpp Who would want to immediately destroy their access to their received emails in the name of forward secrecy?