4 ms·
Is there anything bad about telling people to ignore PGP/GnuPG altogether and use OTR/TextSecure?
by redthrow 12y ago
Is there anything bad about telling people to ignore PGP/GnuPG altogether and use OTR/TextSecure?
- e12e 12y agoYou can't use OTR for email. Well not in a meaningful way, anyway. I think the article[ed:1] misses the point, btw. Yes, managing keys might be tricky - but it's not really rocket science. The thing that's hard is managing trust -- which key one trusts etc. The CA system for web is completely broken. I had some hope for cacert.org -- I think that model (perhaps expanded to include recommending signing gpg-keys as well as x509 certs) has a lot of merit. I think web of trust is the only thing that can work for managing trust. But it needs to be accessible. Have post offices and banks sign gpg keys on when people come in with valid id. Cacert is a different take -- I like to look on it as a "strucutred eternal keysigning party". I trust that model a lot more than the classic CA model. But as it is based on the CA model, it suffers the same problems with centralized trust. Centralized trust is great for organizations, it's not so great for individuals. I think the best model would be a world-wide web of trust for gpg, helped by formal and informal signing organizations (ie: like cacert, signinparties -- and with the help of banks, governments, DMV and similar institutions that traditionally help with issuing IDs). Then there should be support for anchoring DNS/CAs (and CAs for openssh) with gpg. So that if you trust someone is a representative of an organization linked to a domain name, you can trust them to autorize a CA for that name (there's technical details here, but I think the idea should be clear enough). CAs go away, everyone can sign their own certs -- and there's an easy way to link x509 and gpg trust. People will still lose their keys, and get invalid keys signed etc -- key management is hard. But the really confounding thing is trust -- and knowing how to determine which keys are "proper" keys for a given entity. That's really trust management, not (just) key management. [ed:1 whops, that was the other article on making key management easy ;-) But I suppose this comment is relevant wrt how to make encryption more readily available...]
- redthrow 12y agoWhat do you mean by people can't use OTR for email in a meaningful way? Almost nobody can use PGP/GnuPG properly and OTR is reasonably easy to use for most people. Isn't this alone a good reason to just tell people to ignore PGP/GnuPG altogether?
- e12e 12y agohttps://lists.cypherpunks.ca/pipermail/otr-users/2006-January/000508.html https://lists.cypherpunks.ca/pipermail/otr-users/2006-Januar... to whit: Wed Jan 11 00:33:40 EST 2006, CLAY SHENTRUP CLAY at BROKENLADDER.COM wrote: > > On 1/10/06, Daniel Guido <dguido at > gmail.com> wrote: >> >> Correct me if I'm wrong, but there is no >> working implementation of OTR for e-mail >> yet is there? > > There can't be really. The sender and > receiver have to agree upon a shared secret > at the time of transmition, which requires > at least 3 passes.
- redthrow 12y agoOk, I guess you simply meant that there's no OTR implementation for email. So, again, what's wrong with telling people to ignore PGP/GnuPG altogether? -- Assange to Google's Schmidt: 'I don't use email' http://www.computerworld.com/article/2496908/encryption/assange-to-google-s-schmidt---i-don-t-use-email-.html http://www.computerworld.com/article/2496908/encryption/assa...
- e12e 12y agoI meant that there cannot be a reasonable OTR implementation for email. You can stop using email if you want - I love it, as the last vestige of useful decentralised service on the Internet (I run my own email service, and many organisations do too). You can encrypt your email -- but not with OTR. S/MIME and gpg/pgp do work.
- redthrow 12y agogpg/pgp do work for those who can use it properly, which is a tiny minority. Can your parents or non-tech savvy friends use gpg/pgp? Probably not. And as Assange said, if you are e.g. a journalist in the government watchlist, it could be worse (more dangerous) than not using gpg/pgp. Text messages using OTR seems like a better way. For widespread crypto usage, telling people to ignore pgp/gpg and use texts with OTR seems more reasonable than keeping projects like GnuPG alive. If I were running a company like Facebook who's interested in spying on people, I might even fund projects like GnuPG so that unrealistic geeks keep thinking this is a viable solution.
- woah 12y agoWeb of trust is a complete joke. It is literally a system where people who are unqualified to do so confirm identity based on a government id.
- e12e 12y agoAs opposed to the CA system, where machines who are unqualified to do so confirm identity based on an email?
- jMyles 12y agoIt certainly doesn't have to be. A person's trust of long-time friends is an important metric for network security. Not every key-signing party involves government ids.