Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Conversation

Notices

  1. The Doctor (drwho@hackers.town)'s status on Friday, 27-Aug-2021 17:19:32 UTC The Doctor The Doctor

    I feel slightly embarassed that I ever taught classes on PGP.

    In conversation Friday, 27-Aug-2021 17:19:32 UTC from hackers.town permalink
    • Emacsen (emacsen@emacsen.net)'s status on Friday, 27-Aug-2021 17:19:07 UTC Emacsen Emacsen
      in reply to
      • Charles U. Farley

      @freakazoid @drwho

      I've thought a lot about this over the last 4 years or so, and here are my thoughts in a nutshell (maybe I should write this up):

      1. PGP would be simple if it weren't for things like WoT. Without WoT we don't need to worry about signed keys and chains and any of that.

      2. We should have just accepted some defaults ala P3P such as approve new keys automatically and made that tunable for extra security by others.

      ...

      In conversation Friday, 27-Aug-2021 17:19:07 UTC permalink
    • Emacsen (emacsen@emacsen.net)'s status on Friday, 27-Aug-2021 17:19:28 UTC Emacsen Emacsen
      in reply to

      @drwho

      Why?

      In conversation Friday, 27-Aug-2021 17:19:28 UTC permalink
    • Charles U. Farley (freakazoid@retro.social)'s status on Friday, 27-Aug-2021 17:19:28 UTC Charles U. Farley Charles U. Farley
      in reply to
      • Emacsen

      @emacsen @drwho Because it's a usability nightmare, which makes it less secure and also dramatically reduced its ability to have any impact, at best, and at worst it taught people that encryption is hard so they might as well not even try?

      In conversation Friday, 27-Aug-2021 17:19:28 UTC permalink
      Bernie repeated this.
    • Emacsen (emacsen@emacsen.net)'s status on Friday, 27-Aug-2021 17:23:37 UTC Emacsen Emacsen
      in reply to
      • Charles U. Farley

      @freakazoid @drwho

      3. Purists are a real problem. Look at this comment on Hacker News in response to my mobile OS review:

      https://news.ycombinator.com/item?id=28299734

      This commenter would prefer to tell people *not to use mobile phones* than let them use FLOSS OSes with binary drivers.

      These attitudes put people in harm's way.

      4. People believe that security = complexity. There's a paper on OCAP as implemented in HP that talks about this issue. It's a serious problem, and PGP absolutely fit into that mindset.

      In conversation Friday, 27-Aug-2021 17:23:37 UTC permalink
    • Charles U. Farley (freakazoid@retro.social)'s status on Friday, 27-Aug-2021 17:23:37 UTC Charles U. Farley Charles U. Farley
      in reply to
      • Emacsen

      @emacsen @drwho I think it's much better to just tell people to be mindful of their use of technology and to realize that nothing is perfect.

      In conversation Friday, 27-Aug-2021 17:23:37 UTC permalink
    • Bernie (codewiz@mstdn.io)'s status on Friday, 27-Aug-2021 17:24:04 UTC Bernie Bernie
      in reply to
      • Charles U. Farley
      • Emacsen

      @freakazoid @emacsen @drwho Another barrier to GPG adoption is that mainstream email clients (GMail, Outlook, and yes, even Thunderbird) have supported other security schemes. GPG plugins and extensions have been around for a long time, but each one came with interoperability or usability issues.

      Finally Thunderbird has built-in GPG support (still very immature, and using its own key store rather than the system's).

      In conversation Friday, 27-Aug-2021 17:24:04 UTC permalink
    • Bernie (codewiz@mstdn.io)'s status on Friday, 27-Aug-2021 17:25:12 UTC Bernie Bernie
      in reply to
      • Charles U. Farley
      • Emacsen

      @freakazoid @emacsen @drwho Another barrier to GPG adoption was that mainstream email clients (Gmail, Outlook and, yes, even Thunderbird) have supported other useless encryption schemes like S/MIME. GPG plugins and extensions have been around for a long time, but each one came with interoperability or usability issues.

      Finally Thunderbird has built-in GPG support (still very immature, and using its own key store rather than the system's).

      In conversation Friday, 27-Aug-2021 17:25:12 UTC permalink
    • The Doctor (drwho@hackers.town)'s status on Saturday, 28-Aug-2021 04:18:52 UTC The Doctor The Doctor
      in reply to
      • Bernie
      • Charles U. Farley
      • Emacsen

      @codewiz @freakazoid @emacsen T-bird finally ditched Enigmail?

      In conversation Saturday, 28-Aug-2021 04:18:52 UTC permalink
    • Bernie (codewiz@mstdn.io)'s status on Saturday, 28-Aug-2021 04:19:37 UTC Bernie Bernie
      in reply to
      • Charles U. Farley
      • Emacsen

      @drwho @freakazoid @emacsen Yes, finally. But they went the way of reimplementing the full-blown OpenPGP spec rather than use GnuPG (or GPGME).

      It's probably good enough for a beginner user, but it doesn't support all the key formats and algorithms of GnuPG and requires manually importing/exporting private keys if you use PGP with other applications.

      In conversation Saturday, 28-Aug-2021 04:19:37 UTC permalink
    • Bernie (codewiz@mstdn.io)'s status on Saturday, 28-Aug-2021 04:20:37 UTC Bernie Bernie
      in reply to
      • Charles U. Farley
      • Emacsen

      @drwho @freakazoid @emacsen Yes, finally. But they went the way of reimplementing the full-blown OpenPGP spec rather than use GnuPG (or GPGME).

      It's probably good enough for a beginner user, but it doesn't support all the key formats and algorithms of GnuPG and requires manually importing/exporting private keys if you use PGP with other applications.

      #thunderbird #gpg #pgp #openpgp

      In conversation Saturday, 28-Aug-2021 04:20:37 UTC permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.