6 ms·
This is such a bizarre take to me. If you don't want people using your key to encrypt email to you, why are you uploading your key to a service designed to help
by nulbyte 2y ago
This is such a bizarre take to me. If you don't want people using your key to encrypt email to you, why are you uploading your key to a service designed to help people find it to encrypt email to you?
- cl3misch 2y agoTo play around with it?
- jraph 2y ago> to encrypt email to you this part is incorrect: keys have other uses. It's not because you sign Debian packages that you encrypt your emails. With the same key. Hence the need to have a way to say "this key is for encrypting emails with such method and such protocol".
- soraminazuki 2y agoThen only upload a signing key. Don't upload encryption keys. PGP is capable of making that distinction.
- erinaceousjones 2y agoYes, but how many other things can you think of other than email which you would share your encryption public keys for? Honestly email would be at the bottom of applications I would think of, even when registering keys with a key server. If you have a bunch for different use cases (or like, levels of security/secrecy/revoking-this-will-be-a-nightmare), which you've set your one email address as recipient for, which of those is "default"? The keyserver and protonmail also are entirely separate. I wouldn't expect the two entities to be communicating with each other if I hadn't opted in. It feels weird, like when private companies harvest your data without asking.
- soraminazuki 2y ago> Yes, but how many other things can you think of other than email which you would share your encryption public keys for? The only non-theoretical use of a PGP encryption key is email. > (different) levels of security/secrecy/revoking-this-will-be-a-nightmare Using multiple keys don't offer added security or secrecy. Also, keys.openpgp.org lets you delete keys as long as you have access to your email. > It feels weird, like when private companies harvest your data without asking This is nothing like data harvesting, which may be why you prefixed your statement with "it feels like." Nobody is obtaining private or even semi-private data that can be used against you. Also, > private companies keys.openpgp.org is a open source community project. It's not an evil for-profit data-hoarding entity that's implied by those two words. I'm curious, what do you think a PGP keyserver is for? You make it sound as if there are no legitimate use for downloading encryption keys from it. Which leads to another question, why upload the keys at all?
- kelnos 2y ago> The only non-theoretical use of a PGP encryption key is email. I use a backup application that encrypts my backups using PGP. Granted, that certainly doesn't require a published public key. But your assertion is incorrect.
- soraminazuki 2y agoRight, I should've phrased it as PGP encryption keys obtained from a public keyserver.
- lxgr 2y agoBacking up keys stored on a GnuPG card (e.g. on a Yubikey) does require that.
- soraminazuki 2y agoIt doesn't require that. You have the option of doing so. You can back up public keys and restore them just like any other file. I don't see why a public key file should require special treatment from any other file requiring backup.
- lxgr 2y agoBacking up my signed public keys, for example. GnuPG card doesn’t store anything other than the private key, so there’s a risk of losing access. I’m not sure if that protocol Protonmail is using would pick up such keys without email verification, though.
- soraminazuki 2y agoIf you don't mean to publish your keys, you'd be better off backing them along with your other files rather than uploading it to a public keyserver.
- lxgr 2y agoI don't mind publishing my keys at all, and in fact for some of my applications it makes GPG much more ergonomic to use. I do mind software or services taking that as an implicit statement of "go ahead, encrypt email to me using this" when it can clearly cause confusion and irrecoverable messages in many cases. That said, we don't actually know if Protonmail really does search all keyservers (including the "old-style" ones, i.e. the ones where anybody could publish anything in an unverified manner and the "web of trust" is used to figure out which key is in fact trusted), or only the new ones that perform email verification. If it's the latter, I think performing email verification could be considered a bit more of an opt-in statement to receiving encrypted mail.
- smallerfish 2y agoWhere do the docs on that page indicate that? Don't assume all users who are interested in privacy are experts on how keys work. https://keys.openpgp.org/upload https://keys.openpgp.org/upload
- soraminazuki 2y agoWhy should a service for publishing keys host manuals for GPG? The manuals are available at www.gnupg.org, where they belong. https://www.gnupg.org/documentation/index.html https://www.gnupg.org/documentation/index.html Also, why would that be grounds for shaming people who use published keys in a way it was designed for? I don't get your point.
- smallerfish 2y agoThe specific point is that there's nothing on the directory site to indicate that uploading a key to the directory will cause people to start encrypting your emails. From the description it sounds like a directory of pgp keys, nothing more and nothing less. The more general point is that this is why people don't use these systems. There's very little thought given to UX. It's barely usable for average developers, let alone laypeople. Instead there's gatekeeping and stubborn pointing at ideals.
- soraminazuki 2y agoWhat do you think a public directory of PGP keys exist for? To publish them so that other people can use them without asking you for one in person. Why would it need a oh-this-is-not-actually-meant-to-be-public-it's-a-trap-for-shaming-people-who-reasonably-assumed-otherwise flag? Would that flag also need another this-flag-should-not-be-respected flag? Yes, there are UX problems with PGP. No, that's not relevant to this particular case.
- jraph 2y ago> To publish them so that can use them without asking you for one in person without asking you for it, but not without asking you what to use it for.