11 ms·
I disagree. As far as technicality goes, PGP is a pretty strong decentralized model. GnuPG is a pretty solid implementation of PGP. Are they perfect? No. Do th
by codeguro 3y ago
I disagree. As far as technicality goes, PGP is a pretty strong decentralized model. GnuPG is a pretty solid implementation of PGP.
Are they perfect? No. Do they merit this much criticism? Obviously not. This whole thing reads like an opinion piece criticizing implementation details and attributing it to the whole design. I did a spot check on the guy's authoritative sources and found them _extremely biased_, with one referring to an article disparaging DSA, who prefixes his technicals with "more important articles" arguing that white people somehow cannot experience racism even if they experienced racial prejudice. And they expect to be taken seriously? It's insanity.
But back to the technical aspect - _Of Course_ you should not use 1024-bi RSA or DSA keys. Of course you should choose prime numbers. If someone chooses to use a non-prime field you're going to have problems - that's not a problem with the PGP protocol or with RSA or DSA. If you're trusting public keys from complete strangers, _you're doing it wrong_. If you're not verifying that the fingerprint matches, _you're doing it wrong_.
For a journalist trying to report his findings in an unfriendly country to a secured third party, PGP is an excellent choice. For a client to secure communications with his lawyer, PGP is an excellent choice. And for anyone who would argue the contrary, I challenge them to forge a signature for the following identity. Go on, I dare you.
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQENBGRqTLABCADPc27v3wK4EhBAuoWn5GAVz15r/6osSf41eQ5W83dAmUp4IeIq
bHLOvI44nVGiTUrawnpk1oHdOyZxthdo14KL0mplLTAWI0oYzcFClrhNOWa1cB5a
K8ZYL0lwlM2YvhGQMaLzJKqEjO+JxLnqKIZeV9iYt9c16igvatVm37DP0NBVFF+V
/58g3haNDjvQg4fPOvVIJ8SuIK1vPuTrb1ob2PLFBmHwwmzNGWfWHBBm6izxXZ85
ad56Rp/gca7j02qjnSE1X8S9s0OAJ6AAYRkWhtr/EUw3mjOjGSv32lFrsB7qvSu4
kEl/GY0PhcmnpSwi79vvva82fHZrvfKnbuoHABEBAAG0CUFub255bW91c4kBTgQT
AQoAOBYhBNXzRmmKCQC9zIAegYhSrtq97HJWBQJkakywAhsDBQsJCAcCBhUKCQgL
AgQWAgMBAh4BAheAAAoJEIhSrtq97HJWMUQIALwWlE1MyiL2vOjG3srY2m6gnE/p
iDI9YzQECRr88R0CTSFOvGU8rFwwGNBavtMHfl9BJyJFVk82VK/mWCW7j37CJNu9
ObxqIuvZc35Op9G5LHlEFj/Hal4B3LqyIzm0Kb2IsY7HPMGNmLEQW8gw+PvkNJHr
jaEF8eQ/vhboh+rxYn1COiAlBcxpHr3vvCtrsrlqhc1bPRb49ItJ5ybooDaLkl9T
prHruCUzsCobYSiT7A85i6wwFvkICCIQZpPCR7cgVqyffjmjLlTPSWpu/+aCp1GP
c6532MLqPGhEaFGrTWJzq9ApdQnbbNOt9kkMGCL1GLPGkPNQq0k2R0LNkmA=
=A+3o
-----END PGP PUBLIC KEY BLOCK-----
Only I own this private key, and only I can sign with it. It's stored offline, secured and airgapped. It'd take more energy than there is on the planet to crack it. But I can easily prove I'm the owner. Trapdoor functions are a wonderful thing. If I were given your public key, and it _followed protocol_ and was a strong key, I'd be able secure communications to you in such a way _even I wouldn't be able to decrypt them_.
----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Go on, forge something. I'm waiting.
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEE1fNGaYoJAL3MgB6BiFKu2r3sclYFAmRqTYgACgkQiFKu2r3s
clYdUAf+IBIVIxZ1tSbNsKc/Cay0f6weJwUxmr59v7Q/UNzDUcn468Ei0CO9WSVi
klMob9uxBrnB9nGYeHcYULUxGZxAwbooQU8XDrE4x4btvARUaRgP0x+ikw6XY/1t
N60SeHG9BVxL0EULrlQpNAbbBEQVk59jcKHTHQg8yTcKujw0DiBlJnmQTW5UOaoq
UMJRKDBRJAOsrRBDLO2JjWRuFB8dhcVRNv5gqqPg+YyIdcsd/XQyXObyIyHznoAl
gjyu9R8hi2Y0vrpNW8mniapDXsm09hOzpaMZqkNSGDRQJVLYWaUMJMs7epwKnL4z
x3Virwk8u9NDj4NqjUmzaw2wpvI5iQ==
=f62G
-----END PGP SIGNATURE-----
- dale_glass 3y agoAnd what use is that? Here's your key: pub rsa2048 2023-05-21 [SC] D5F346698A0900BDCC801E818852AEDABDEC7256 uid Anonymous Why is that any more valid than any other key that says "Anonymous"? When you "prove" you own it, how would I know there's not MITM happening over the internet?
- codeguro 3y ago-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Its use is securing communications over an insecure channel. I can guarantee you that this message has not been tampered with in any way by HackerNews admins if the public key validates the signature of this message. If they have tried to tampered with it, the fact that they don't have the public key would demonstrate an invalid signature. So not only would you know if this message is really from me, you'd also know if it was tampered with. -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEE1fNGaYoJAL3MgB6BiFKu2r3sclYFAmRqepgACgkQiFKu2r3s clZ8YQgAkeR2l3eRGZdw0pKGYwO5H7ShqWeQrNK8O5lJVxUmQki+U43CJwlRmhrh iC8dPcSoiv+oXj6ziNxz4zgXnTNsb5OH2/lN7kMBEhsLjFNYMHxbaRfCWeznDrde uYzu0l5RqgTAL8fAxgIQ0smJuT9a8UDqzKmWO8N68nUG/L+aR0EfPb37MnTwXOk6 JGZFhKBEl4ZZ1Fq45YgGQNNX7jDerzxQG5Iu8pEZuVLi3g3d6CrgAEJhP865BjYX FPZ+IcalTkNH9x3IQ8E+QZXatu98mEPCOKLz0jbuJHAhH1TlKy0ya/vNVgVlstgj 9nl5ujnpkCsRn4iUZ+Iq+0vNOxkMbA== =yisw -----END PGP SIGNATURE-----
- dale_glass 3y agoThe guarantee is worthless, HN could generate a new key with the same "Anonymous" name on it, and use it to sign whatever they wanted to sign, and modify your comment to post that. I have no way of finding out whether this already happened or not. Signing messages with a new key untrusted by anyone is worthless security-wise. In general posting GPG signed messages in forums is of dubious utility, unless you're a celebrity of some sort and have a key with a decent amount of signatures on it. Even then, GPG makes path finding extremely inconvenient, so even though I'm very well connected on the PGP WoT, it'd take me a serious amount of work to verify a signature unless it belongs to one of the few hundred people whose keys I've actually signed (yup, I used to be quite serious about this).