Hacker Poesy
  • FAQ
  • Login
  • Public

    • Public
    • Groups
    • Recent tags
    • Popular
    • Directory

Conversation:

Notices

  1. zoowar (zoowar)'s status on Sunday, 03-Nov-2013 11:39:09 EST zoowar zoowar
    Remote profile options...
    Ask HN: Why is PGP not used widely? !darknet !crypto https://news.ycombinator.com/item?id=6662798
    Sunday, 03-Nov-2013 11:39:09 EST from indy.im permalink
    • morph (morph)'s status on Sunday, 03-Nov-2013 12:05:32 EST morph morph
      Remote profile options...
      • zoowar
      @zoowar Most people don’t want to be bothered with anything that is suspected to be too technical and complcated at all. But the use of PGP is really not nice, although you don’t need really dig too deep into crypto.
      Sunday, 03-Nov-2013 12:05:32 EST permalink
    • zoowar (zoowar)'s status on Sunday, 03-Nov-2013 12:33:58 EST zoowar zoowar
      Remote profile options...
      • morph
      I don't follow your second sentence.
      Sunday, 03-Nov-2013 12:33:58 EST permalink
    • morph (morph)'s status on Sunday, 03-Nov-2013 13:41:15 EST morph morph
      Remote profile options...
      • zoowar
      @zoowar I meant you would not need to learn a lot about cryptography to handle PGP mail, but people think it is too complicated and/or are too lazy to look at it.
      Sunday, 03-Nov-2013 13:41:15 EST permalink
    • zoowar (zoowar)'s status on Sunday, 03-Nov-2013 13:44:44 EST zoowar zoowar
      Remote profile options...
      • morph
      I like the idea of renaming public/private to something like lock/key which would resonate more clearly with the unthinking masses.
      Sunday, 03-Nov-2013 13:44:44 EST permalink
    • morph (morph)'s status on Sunday, 03-Nov-2013 14:29:52 EST morph morph
      Remote profile options...
      • zoowar
      Yes, and just a “encrypt” button to enable it. I also think maybe it would be a good idea to include a GPG package by default within the installation routine of mail clients.
      Sunday, 03-Nov-2013 14:29:52 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 17:52:43 EST Joshua Judson Rosen Joshua Judson Rosen
      • morph
      I think one of the things that killed #e-mail !crypto was the refusal to store messages decrypted even after they've gone end-to-end.
      Sunday, 03-Nov-2013 17:52:43 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 18:00:43 EST Joshua Judson Rosen Joshua Judson Rosen
      • morph
      e.g., #e-mail !crypto in #Thunderbird still means I can't #search *local* messages lest I be vulnerable to someone breaking into my house.
      Sunday, 03-Nov-2013 18:00:43 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 18:13:08 EST Joshua Judson Rosen Joshua Judson Rosen
      • morph
      Not being allowed !crypto for #privacy on an insecure public net unless I also fear for physical #security in my house/office is #bullshit.
      Sunday, 03-Nov-2013 18:13:08 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 20:52:57 EST Joshua Judson Rosen Joshua Judson Rosen
      Love how the #Enigmail FAQ says "IF a message was confidential enough to be encrypted…" ☹ https://www.enigmail.net/forum/viewtopic.php?f=10&t=637 !crypto #FAIL
      Sunday, 03-Nov-2013 20:52:57 EST permalink
      Joshua Judson Rosen likes this.
    • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca (bobjonkmanformer)'s status on Sunday, 03-Nov-2013 21:34:17 EST Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      Remote profile options...
      • Joshua Judson Rosen
      Thunderbird correctly keeps the message store encrypted, but should be performing decryption on-the-fly for searching, or keep an encrypted, hashed index for speedy searches. But that requires a level of !crypto integration that Enigmail doesn't yet offer.
      Sunday, 03-Nov-2013 21:34:17 EST permalink
    • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca (bobjonkmanformer)'s status on Sunday, 03-Nov-2013 21:39:33 EST Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      Remote profile options...
      More accurately, Thunderbird correctly stores encrypted messages in an unencrypted message store. Would be nice if the message stores were encrypted too, so I'd be less concerned about keeping mail on another computer.
      Sunday, 03-Nov-2013 21:39:33 EST permalink
    • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca (bobjonkmanformer)'s status on Sunday, 03-Nov-2013 21:44:55 EST Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      Remote profile options...
      • morph
      What @SteveKlabnik said: Use GnuPG/PGP even if you *don't* understand it. You might be using a weak key, or accidentaly signing your mail with my public key, but even poor !crypto practices are better than no !crypto at all (but beware the false sense of security given by simple, easy-to-use, weak !crypto) See his pretty good speech at https://www.youtube.com/embed/LjZk8PP-u3c
      Sunday, 03-Nov-2013 21:44:55 EST permalink
    • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca (bobjonkmanformer)'s status on Sunday, 03-Nov-2013 21:48:07 EST Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      Remote profile options...
      • zoowar
      And if you're doing it wrong, there are lots of us !crypto geeks willing to provide advice: https://www.cryptoparty.in/
      Sunday, 03-Nov-2013 21:48:07 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 23:45:55 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      You say "correctly", I still say #bullshit. If I wanted my local files encrypted, I'd encrypt my local filesystem.
      Sunday, 03-Nov-2013 23:45:55 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 23:48:40 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      The transport doesn't get to dictate how data gets stored/used beyond its endpoints. Imagine if SSH left stdout encrypted....
      Sunday, 03-Nov-2013 23:48:40 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 23:52:28 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      Imagine if TLS required that `anything that was sensitive enough to encrypt during HTTPS transit' was also stored encrypted on both ends.
      Sunday, 03-Nov-2013 23:52:28 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 23:53:26 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      I just want end-to-end #security, not `up-my-end' security. Like TLS, which "correctly" doesn't impose encryption beyond the transport.
      Sunday, 03-Nov-2013 23:53:26 EST permalink
      kuro and eniac like this.
    • Joshua Judson Rosen (rozzin)'s status on Sunday, 03-Nov-2013 23:55:37 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      I don't want to have to maintain my PGP keys and passwords, after revoking them, just to read my old #e-mail. Having to is what killed PGP.
      Sunday, 03-Nov-2013 23:55:37 EST permalink
      kuro likes this.
    • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca (bobjonkmanformer)'s status on Monday, 04-Nov-2013 00:24:18 EST Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      Remote profile options...
      • Joshua Judson Rosen
      GnuPG/PGP isn't transport-layer encryption. For e-mail it's a message container that has to be opened separately; similar for files. If you want to store a message plain text, save it as plain text. The problem is that mail clients or their !crypto plugins have tried to make the encryption layer seamless with the transport layer or the message store. The analogy of a (plaintext) pos…
      Monday, 04-Nov-2013 00:24:18 EST permalink

      Attachments

      1. bobjonkman-20131104T052524-ae3x3h8.html
    • Joshua Judson Rosen (rozzin)'s status on Monday, 04-Nov-2013 17:22:04 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      @bobjonkman, I'm not disagreeing. I'm saying: you're right, and that's the problem. ☹
      Monday, 04-Nov-2013 17:22:04 EST permalink
      Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca likes this.
    • Joshua Judson Rosen (rozzin)'s status on Monday, 04-Nov-2013 17:46:45 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      #HOWTO craft a solution-in-search-of-a-problem that nobody wants to use: Step 1, get your #user-story wrong.
      Monday, 04-Nov-2013 17:46:45 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Monday, 04-Nov-2013 17:51:31 EST Joshua Judson Rosen Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      I'm not convinced that PGP couldn't be used to implement `just end-to-end secure' e-mail if the !crypto community could actually value that.
      Monday, 04-Nov-2013 17:51:31 EST permalink
    • lnxw37 (lnxwalt on quitter) (lnxw37)'s status on Monday, 04-Nov-2013 18:10:31 EST lnxw37 (lnxwalt on quitter) lnxw37 (lnxwalt on quitter)
      Remote profile options...
      • Joshua Judson Rosen
      • Former Bob Jonkman -- Please use the new server at https://gs.jonkman.ca
      @rozzin @bobjonkman ISTM that there should be a way to make a PGP / WOT alike secure end-to-end transport. But I'm not a security guru.
      Monday, 04-Nov-2013 18:10:31 EST permalink
    • zoowar (zoowar)'s status on Monday, 04-Nov-2013 18:13:09 EST zoowar zoowar
      Remote profile options...
      • Joshua Judson Rosen
      Would protect the data, but not the meta data. Still should use tls.
      Monday, 04-Nov-2013 18:13:09 EST permalink
    • zoowar (zoowar)'s status on Monday, 04-Nov-2013 21:03:44 EST zoowar zoowar
      Remote profile options...
      • Joshua Judson Rosen
      An important issue rarely voiced. Good job.
      Monday, 04-Nov-2013 21:03:44 EST permalink
    • Joshua Judson Rosen (rozzin)'s status on Friday, 28-Sep-2018 16:22:38 EDT Joshua Judson Rosen Joshua Judson Rosen
      Holy crap! "Since version 1.8, Enigmail can decrypt mails permanently." https://enigmail.net/index.php/en/faq-en?view=topic&id=15 #enigmail #pgp #crypto
      Friday, 28-Sep-2018 16:22:38 EDT permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

Hacker Poesy is a GNU social hub. It runs version 1.1.3-beta3, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Hacker Poesy content and data are available under the Creative Commons Attribution 3.0 license.

Switch to mobile site layout.