6 ms·
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Its use is securing communications over an insecure channel. I can guarantee you that this message has not bee
by codeguro 3y ago
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Its use is securing communications over an insecure channel. I
can guarantee you that this message has not been tampered with
in any way by HackerNews admins if the public key validates
the signature of this message. If they have tried to tampered
with it, the fact that they don't have the public key would
demonstrate an invalid signature. So not only would you know
if this message is really from me, you'd also know if it was
tampered with.
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEE1fNGaYoJAL3MgB6BiFKu2r3sclYFAmRqepgACgkQiFKu2r3s
clZ8YQgAkeR2l3eRGZdw0pKGYwO5H7ShqWeQrNK8O5lJVxUmQki+U43CJwlRmhrh
iC8dPcSoiv+oXj6ziNxz4zgXnTNsb5OH2/lN7kMBEhsLjFNYMHxbaRfCWeznDrde
uYzu0l5RqgTAL8fAxgIQ0smJuT9a8UDqzKmWO8N68nUG/L+aR0EfPb37MnTwXOk6
JGZFhKBEl4ZZ1Fq45YgGQNNX7jDerzxQG5Iu8pEZuVLi3g3d6CrgAEJhP865BjYX
FPZ+IcalTkNH9x3IQ8E+QZXatu98mEPCOKLz0jbuJHAhH1TlKy0ya/vNVgVlstgj
9nl5ujnpkCsRn4iUZ+Iq+0vNOxkMbA==
=yisw
-----END PGP SIGNATURE-----
- dale_glass 3y agoThe guarantee is worthless, HN could generate a new key with the same "Anonymous" name on it, and use it to sign whatever they wanted to sign, and modify your comment to post that. I have no way of finding out whether this already happened or not. Signing messages with a new key untrusted by anyone is worthless security-wise. In general posting GPG signed messages in forums is of dubious utility, unless you're a celebrity of some sort and have a key with a decent amount of signatures on it. Even then, GPG makes path finding extremely inconvenient, so even though I'm very well connected on the PGP WoT, it'd take me a serious amount of work to verify a signature unless it belongs to one of the few hundred people whose keys I've actually signed (yup, I used to be quite serious about this).
- codeguro 3y ago>The guarantee is worthless, HN could generate a new key with the same "Anonymous" name Actually, it's not. That new key is an entirely different identity, and if you're struggling making the distinction between its "name" and its "identity", I'd argue you're not the target audience for PGP in the first place. There are 45,000 John Smiths in the world. Are you going to also argue that the concept of identity is thwarted by this fact? No. I believe this argument is made in bad faith. >and use it to sign whatever they wanted to sign, and modify your comment to post that. I have no way of finding out whether this already happened or not. Have you tried checking the signature? (hint: it's invalid - HackerNews manipulates the whitespace). Verifying signatures is incredibly easy in GnuPG. Would you like me to walk you through it? >In general posting GPG signed messages in forums is of dubious utility, unless you're a celebrity of some sort and have a key with a decent amount of signatures on it. On the contrary, it's quite useful. Public key cryptopgraphy allows you to be absolutely certain that a messages with a valid signature were signed by the holder of the private key. You don't need to know who that person is, but you can be certain that he holds the corollary private key. Your argument seems to be conflating _that_ with an argument on the metadata e.g. the authenticity of the public key itself, and that's an entirely different discussion orthogonal to the _utility_ of PGP. By the way, GPG is just an implementation of the OpenPGP protocol. There's more than one implementation (RNP, sequoia, and OpenPGP.js, to name some for instance). >Even then, GPG makes path finding extremely inconvenient, so even though I'm very well connected on the PGP WoT, it'd take me a serious amount of work to verify a signature So? I never said it was easy. At the end of the day, you'd have to trust someone. PGP allows you to trust your web of friends. TLS requires you to trust some certificate authority. You're not really making any case against PGP here. Moreover, it's net even close to the use-case I argued. For a journalist trying to report his findings in an unfriendly country, PGP is an excellent choice. For a client to secure communications with his lawyer, PGP is an excellent choice. And I'm still waiting for you to forge that signature to prove me wrong.
- dale_glass 3y ago> Actually, it's not. That new key is an entirely different identity Yes, which is just as worthless as the one you used, and from my point of view neither is better than the other. > Have you tried checking the signature? No, there's no point. It is worthless whether it verifies or not. > On the contrary, it's quite useful. Public key cryptopgraphy allows you to be absolutely certain that a messages with a valid signature were signed by the holder of the private key. Yes, and anyone can make a key, and they're all equally worthless unless there's a way for me to develop trust into one of them. And in this situation, there's none. > So? I never said it was easy. At the end of the day, you'd have to trust someone. In the situation you're providing here, there's no way for me to trust anyone, so your signature might as well not be there.
- codeguro 3y ago>Yes, which is just as worthless as the one you used Wrong. One produces a valid signature, the other does not. I couldn't care less for your point of view - my interest align with my clients. >No, there's no point. It is worthless whether it verifies or not. An invalid signature indicates the message has been tampered with. >they're all equally worthless unless there's a way for me to develop trust into one of them Have you tried engaging with the parent post instead of talking past it? Attributing trust to some key an entirely orthogonal issue to the utility of a PKI protocol. > In the situation you're providing here, there's no way for me to trust anyone, so your signature might as well not be there. Sigh. First off, it tells you two things. (1) The message was signed by the holder of the private key if the signature is valid, and (2) the message has been tampered with if the signature is invalid. And you don't even need to trust the key to deduce these facts. Second, you still haven't forged that signature, so the fact that you're arguing past me instead of posting a valid & forged signature only proves my point. You can't do it.
- dale_glass 3y ago> Wrong. One produces a valid signature, the other does not. Wrong. They obviously wouldn't be stupid enough to just modify the message. They'd create their own key, and create a valid signature with that. Then as an end-user, what it looks like to me is that you signed one message with key BDEC7256 and another with key 1E81885. No way for me to tell which one of those is the actual you, because I don't know who you are. > An invalid signature indicates the message has been tampered with. Which is why they'll make a valid signature with their own key. If they're smart about it, they'll take your text, feed it to their key and silently rewrite your comment. I won't ever get to see your intended signature, only theirs. And to make it extra-devious, they could arrange so that you see your original submitted version, but I see the fake one.
- tzs 3y agoPGP is way too verbose for that. If you has used signify for that message, the signature would have been something like this: RWQcQxD3ZdsGnrNBFaLsVZBQ/9WH4q42N9/BFvgeBMhyZ7KUxe85AgpND09npvMNLF0CTfXOSNnF4U6sIioblL98gPVPHrtaZg4 Also the public key would have been small enough to include in the post. Here is the public key I used to make the above signature: RWQcQxD3ZdsGnqH7z1jvcyeUNhAUMPZW4jn/THZAjs+MCi7VXk448K7B For most forum posts where people aren't using real identities all I generally care about is that post X and post Y came from the same person. By including both the signature and the public key I can check that without having to look at anything other than X and Y. (That's assuming that the forum itself is not monkeying with posts).