4 ms·
What do you mean by people can't use OTR for email in a meaningful way? Almost nobody can use PGP/GnuPG properly and OTR is reasonably easy to use for most peo
by redthrow 12y ago
What do you mean by people can't use OTR for email in a meaningful way?
Almost nobody can use PGP/GnuPG properly and OTR is reasonably easy to use for most people. Isn't this alone a good reason to just tell people to ignore PGP/GnuPG altogether?
- e12e 12y agohttps://lists.cypherpunks.ca/pipermail/otr-users/2006-January/000508.html https://lists.cypherpunks.ca/pipermail/otr-users/2006-Januar... to whit: Wed Jan 11 00:33:40 EST 2006, CLAY SHENTRUP CLAY at BROKENLADDER.COM wrote: > > On 1/10/06, Daniel Guido <dguido at > gmail.com> wrote: >> >> Correct me if I'm wrong, but there is no >> working implementation of OTR for e-mail >> yet is there? > > There can't be really. The sender and > receiver have to agree upon a shared secret > at the time of transmition, which requires > at least 3 passes.
- redthrow 12y agoOk, I guess you simply meant that there's no OTR implementation for email. So, again, what's wrong with telling people to ignore PGP/GnuPG altogether? -- Assange to Google's Schmidt: 'I don't use email' http://www.computerworld.com/article/2496908/encryption/assange-to-google-s-schmidt---i-don-t-use-email-.html http://www.computerworld.com/article/2496908/encryption/assa...
- e12e 12y agoI meant that there cannot be a reasonable OTR implementation for email. You can stop using email if you want - I love it, as the last vestige of useful decentralised service on the Internet (I run my own email service, and many organisations do too). You can encrypt your email -- but not with OTR. S/MIME and gpg/pgp do work.
- redthrow 12y agogpg/pgp do work for those who can use it properly, which is a tiny minority. Can your parents or non-tech savvy friends use gpg/pgp? Probably not. And as Assange said, if you are e.g. a journalist in the government watchlist, it could be worse (more dangerous) than not using gpg/pgp. Text messages using OTR seems like a better way. For widespread crypto usage, telling people to ignore pgp/gpg and use texts with OTR seems more reasonable than keeping projects like GnuPG alive. If I were running a company like Facebook who's interested in spying on people, I might even fund projects like GnuPG so that unrealistic geeks keep thinking this is a viable solution.
- e12e 12y agoI'm not convinced most people that can't use gpg "properly" are able to use OTR "properly". As for facebook, as long as they keep the XMPP access open and supported[1], at least they do support OTR. Unlike eg: google. I don't really understand this "gpg is impossibly hard"-stance. Yes, security is hard. Why recommend OTR? Don't get me wrong, I love OTR -- but verifying OTR keys, and transporting identities across devices (eg: when getting a new phone) is pretty difficult too. Are you saying wrong use of OTR is better than wrong use of gpg, because most people that use OTR use it in a way that allow for MITM anyway? [1] https://www.facebook.com/sitetour/chat.php https://www.facebook.com/sitetour/chat.php
- redthrow 12y agoI don't think you need to be convinced. When 99% of people look at the choice between (a) Thunderbird+Enigmail and (b) TextSecure, they know which one is easier to use (your Mom probably knows more than you do in this regard), not to mention OTR has properties that PGP/GPG lacks such as PFS.
- e12e 12y agoTextsecure is nice, but it's not really an alternative to encrypted email. It doesn't support off-line use, it's inconvenient for sharing large documents. But most importantly, the point you seem to ignore, it's not secure if you don't verify keys. I'd say most people don't verify keys with OTR -- hence they're not using it in a manner that's actually secure. I do agree that it's a lot better than people using Snapchat.
- dragonwriter 12y agoI kind of thought that the web itself was a major example of a useful decentralized service on the internet; kind of odd for email to be described as the last beside of that.
- e12e 12y agoIt was. It technically still is. But large parts of what makes the web useful -- content and search/indexing is being trapped in silos like Google, G+, Twitter, Facebook, Blogspot etc.
- jMyles 12y agoTo the extent that HTTPS is the protocol of the web, its primary implementation (the CA system) is, in every meaningful way, centralized along exactly the same lines as much of the rest of society: in governments and corporations.