5 ms·
This sucks. At the same time, only experts use OpenPGP so I guess maby it's not a big deal? I've been using PGP for decades at this point and I'm still somewha
by dosman33 3y ago
This sucks. At the same time, only experts use OpenPGP so I guess maby it's not a big deal?
I've been using PGP for decades at this point and I'm still somewhat surprised when I encounter security professionals that either can't figure out how to use PGP or just ignore it because "its too complicated, and I already have Signal". I have no beef with encrypted messenger services but it's not the same use case as PGP for email and other needs.
This also hints at a separate cultural divide. Young people only know email as that thing you need in order to setup other accounts. They use IM for the bulk of their real communication and at best consider email something they only use for work. Only old farts think of email as something they use for personal correspondence. And frankly, most of the people I interact with are younger than me so most of my communication has shifted to where the people are that use it, which is IM services.
- tptacek 3y agoExperts avoid PGP like the stomach flu. It'd be interesting if you could find a single cryptography engineer of note that has spoken up for it in the last 10 years.
- LtWorf 3y agoExperts like certificate authorities, which have proven themselves to be completely unreliable several times.
- akerl_ 3y agoI'm not aware of any experts who like individual certificate authorities. Are there some that I'm missing? I think perhaps what you mean to say is that experts like the x509 PKI. Which again, isn't quite true. You'll find plenty of experts pointing out that major parts of x509 and the PKI ecosystem, and of TLS and HTTPS, are garbage: ASN.1 parsing is a trashfire, protocol/cipher negotiation has had numerous critical flaws, things like compression have allowed traffic to be decrypted. What I think is more accurate to say is that experts have invested heavily in finding ways to augment web infrastructure to remove broad categories of these, and the result is a generally recommendable system. This includes things like moving to TLS 1.3, enforcing that CAs participate in Cert Transparency logs, delisting CAs that misbehave, and adjusting browser behavior to avoid security pitfalls like mixed content that compromise users. The problem with doing that for GPG is partly that its fundamental nature is not well aligned with making those kinds of changes, and partly that (as we see in the original post) GnuPG is resistant to making changes that would leave behind users of insecure codepaths and cryptography.
- tptacek 3y agoI would like you to name a cryptography engineer of any note that advocates for the underlying technical details of the X.509 CA system. For that matter, I'd be interested in whether you could name one of any note that works for any CA, LetsEncrypt possibly excluded.
- beeboobaa 3y agoWhy do you, and your supposed cryptography engineers, talk shit about everything that is actually used instead of doing something useful like making those things better or providing alternatives? It's getting really hard to take you seriously. You hate gpg, you hate pki and you always claim to know better than industry standards without providing any details whatsoever.
- tptacek 3y agoI don't know where "you hate PKI" comes from. Certainly I dislike X.509! It's a terrible protocol/format, and I doubt even its own designers would repeat the mistake. But I use the WebPKI, and have spent most of my time on HN talking about it defending it. I'm pretty comfortable with who does and doesn't take me seriously, for what it's worth. You don't have to if you don't want to.
- beeboobaa 3y agoOkay you hate X509. Should we just ditch https then?
- tptacek 3y agoIt's as if you stopped reading 1/3 of the way into the comment you're replying to.
- beeboobaa 3y agoWhat? You want me to acknowledge this? > I'm pretty comfortable with who does and doesn't take me seriously, for what it's worth. You don't have to if you don't want to. Cool. Happy for you bro.
- dosman33 3y agoThis is all amusing. Not that it matters, but when I said "expert" I really meant any user that understands how to use PGP. Those of us born during the construction of the pyramids know how to use it because it was the only option that existed back then, and we still have that knowledge despite other options existing. Signal and other options are great, but you can't encrypt arbitrary data with it. PGP is really a different use case these days. And the ancients that still write emails.