5 ms·
Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a re
by knowtheory 13y ago
Normally i'd let it go, but i actually would like some clarity on your intent here. Are you implying that Schneier doesn't use encrypted communications on a regular basis, that PGP is impractical, or both?
(and to be clear, my intent is not to bait, i'm actually curious)
- dmix 13y agoAs it's commonly called: "endpoint security". If his computers have ever been compromised, his PGP private key would likely be as well. Considering all the news about US gov spending millions on rootkits, it was likely a wise choice to generate a new one in case a previous one was likely to have been compromised. I'd guess Schiener would be a target of interest by some state (as is anyone working with encryption it seems).
- jlgreco 13y agoAlternatively, it could mean that while he uses it often, he does not often use it for things that are actually important. Faced with unusually important communication, he may have decided to create a new key that he could be confident was still private.
- tptacek 13y agoMost people don't use PGP on a regular basis. I'm use PGP a lot, more than I think most HN readers, but most of the people I talk to (even in my own field, which is full of secrets and adversaries) don't have PGP keys.
- miloshadzic 13y agoDoes the reason for that ever come up in a conversation? I thought that everyone working in security used PGP a lot.
- betterunix 13y agoIn fact, it is unusual to see people even sign emails in the (academic) cryptography community, let alone encrypt messages (at least in my experience). It is surprisingly rare to see academic crypto researchers actually use the systems they design, even for basic things like signing and encryption.
- Torgo 13y agoStrategically, you are probably better off not signing a message unless you want the message to be verifiable.
- reeses 13y agoThere's also the paranoia of non-repudiability with signed messages. In general, there is minimal benefit just signing a document. I don't care if someone I work with is spoofed because it will become obvious very quickly. It's only in a very few cases where there's an advantage in signing a document, and it's usually more in the verifiability of content (so that you can verify that nothing is lost/changed in transit) than in the verification of identity. Given the lack of adoption of PGP/GnuPG in email clients vs. S/MIME, if I'm signing my emails without encrypting them, chances are the recipient would still be able to read my emails and, knowing my writing style and given the context, be able to suss out that I was in fact the author. I use the word "paranoia" intentionally because there's a lack of meaningful legal precedent establishing that a gpg-signed message is enough to establish authorship. In a civil case, sure, it looks bad, but you could easily say,"oops, I stored my public key on [vps or cloud service], which was a well-known victim of a hack."
- m0nastic 13y agoIn a dozen years, I think I've had a grand total of 4 clients (out of several hundred) that ever used PGP (despite recommending it specifically on project kickoff calls, particularly for communicating discovered vulnerabilities). I only had one who already had a key. Outside of those few work examples, I don't think I've ever sent or received a PGP encrypted message. In fact, the only signed messages I think I've ever seen were mailing list messages from people who signed all their messages.
- bigiain 13y agoSince 1997, I've collected public keys from a grand total of 17 friends/colleagues/business-contacts. (Note: FWIW, the email address in your profile doesn't provide a public key from pgp.mit.edu – I would have added you to my keychain and sent you a "Hi! Isn't it nice to introduce yourself without the NSA listening in!" email…)
- m0nastic 13y agoI just searched pgp.mit.edu and it looks like the first key I have on there is from 1998[1] (with several others from previous jobs, although I don't know why I had two keys when I worked at BBN). I don't think I even have a key for my current email address. [1] http://pgp.mit.edu:11371/pks/lookup?op=vindex&search=0x867C69B495193A2A http://pgp.mit.edu:11371/pks/lookup?op=vindex&search=0x867C6...
- dublinben 13y agoI met Bruce this last weekend at a conference, and every single business card I collected had the individual's PGP key on it.
- tptacek 13y agoWell, I'm a professional security researcher, and I end up using ZIP+AES more often than I do PGP.
- danellis 13y agoHow do you securely share the AES key?
- BrandonY 13y agoAES is really great compared to RSA, so I put my AES key on my website instead of my RSA public key. It's made it very easy for people to contact me securely.
- sp332 13y agoAES is symmetric...
- BrandonY 13y agoYeah, that makes it really convenient for me if I have to decrypt an important message from a public computer.
- xerophtye 13y agoexactly... I am just as confused as you are. What's the point of using AES if you are putting its key out on the open? O_O that's like using a very sophisticated lock on your front door and put up a sign saying "The key is under the Mat"
- 13y ago
- fluidcruft 13y agoOh, look. It's the government contractor sowing FUD.
- tptacek 13y agoHuh? I think you responded to the wrong comment.
- betterunix 13y agoConsidering the fact that most people at CRYPTO, Usenix Security, IEEE Security and Privacy, and other prominent cryptography and security conferences do not have PGP or S/MIME keys...it would not be surprising if Schneier was not using PGP on a regular basis.
- mpyne 13y agoI've had a PGP key since 2001. I upgraded to 2048 bit some years ago due to the increasing weakness of 1024 bit keys. I think I've received maybe one message encrypted to me. Everything else I use PGP for is to send signed emails to mailing lists.
- reeses 13y agoThe post to which you were replying was amusing at the cost of a lack of rigor. Bruce generally does not sign/encrypt his email because he views email as a low-security communications mechanism anyway.[1] He generally advises a rational risk assessment when determining how much security to apply to a process. He often uses the example of locking doors on your house, etc. In re PGP, he's been critical of a number of shortcomings in PGP and GnuPG since the beginning, but by the same token, one of his first hires at Counterpane was Jon Callas. [1] http://www.esecurityplanet.com/trends/security-tips-from-bruce-schneier.html http://www.esecurityplanet.com/trends/security-tips-from-bru...
- donniezazen 13y agoI would like to use PGP. In my line of work folks use computers as television sets. They open browser, pdf reader, office software. I am afraid if I am to use PGP just for signing my emails it might look like spam to them.