So here you have the full picture now: #PGP doesn't work and never will. Stop recommending it, stop organizing key signing parties, you aren't helping anybody doing that. Just put it to grave instead.

#RIPPGP #crypto #infosec

latacora.singles/2019/07/16/th

The scary thing: some products in need of #crypto such as password managers are being built on top of #PGP because that's supposedly easier to get right. But it's not. Looking at #Passbolt for example, there are definitely better way to do public key crypto.

#infosec

Show thread

And #email is indeed beyond saving, I don't see secure communication over email to happen, ever. No way around establishing new protocols for encrypted communication, e.g. #Signal.

#crypto #infosec

palant.de/2018/11/12/as-far-as

Show thread

@WPalant Would an encrypted protocol that federates via DNS & routes to user mailboxes (like email) be possible though? I don't want my cell phone carrier to be in control of my netizen identity like Signal requires.

@adam In principle - anything would be possible. The problem is merely getting enough weight behind a solution for it to gain traction. So far I don't see anything like that on the horizon.

@WPalant Yes, understood. The JMAP standard working group isn't even bothering with encryption it seems. Some proprietary clients like SpikeNow.com switch to a centralized server for encrypted email which makes it easy from a user-side except both users need the same app. :-\

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml