3 ms·
PGP/GPG by default have no perfect forward secrecy though. In Signal you can check the certificates checksums in conversation settings, to compare them e.g. wh
by precommunicator 2y ago
PGP/GPG by default have no perfect forward secrecy though.
In Signal you can check the certificates checksums in conversation settings, to compare them e.g. when physically present to the other device.
There are other solutions that use Signal protocol or that have PFS that are decentralized. And you can build your own, it's open source at the end.
Signal stated already that they would sooner exit certain markets than violate their security (e.g. https://swedenherald.com/article/signals-ceo-then-were-leaving-sweden https://swedenherald.com/article/signals-ceo-then-were-leavi...)
- spapas82 2y agoYes, if you care about forward secrecy then pgp is not a good solution. > Signal stated already that they would sooner exit certain markets than violate their security You still need to rely on a third party's goodwill to keep that promise. Also even if they are willing to keep the promise it is possible that they won't be able.
- 3np 2y agoThe point was not really about using PGP specifically but referring to its web-of-trust model, I believe. Forward secrecy does not require centralized key distribution and/or trust lists.
- upofadown 2y agoIf you keep your messages around in some form then that effectively defeats forward secrecy. In any case where the attacker can get your secret encryption key material, they will be able to get any messages you still have access to. Most people want to keep their old messages around. So for messaging, forward secrecy is of little practical value. If you do keep your messages around, then PGP's encrypt once[1] scheme is much better than what most other systems do. The message is encrypted and stays encrypted. It is never in a decrypted state unless the user wants to look at it. This normally involves the entry of a secure passphrase. Contrast that with typical instant messengers where the security of retained messages is entirely up to the device security. The implementation of a forward secrecy scheme ironically makes this more likely. Once the session key is deleted, the easiest way to keep the message around is to leave it as plaintext. So the user either has to turn on self deleting messages and lose those messages, or has to leave those messages available to potential attackers. BTW, "forward secrecy" is a terrible term for usability. Something like "message burning" much better fits with a typical users conceptual context. [1] https://articles.59.ca/doku.php?id=pgpfan:encryptonce https://articles.59.ca/doku.php?id=pgpfan:encryptonce
- immibis 2y agoThere's a form of deniable authentication where you have the ability to forge the signatures of messages once you receive them, so you could alter them on your device. It's irrelevant, though, because no chat app actually has this feature, so no criminal does it. And the cops don't go by the encrypted bits, anyway - they go by what it says on your screen, or their screen. (Which does mean that if you hack into your own app's database and forge messages, you can convincingly incriminate people, yes) Research into deniability protocols is cool research, but with no relevance to the real world of cops vs robbers.