Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. πŸ“ New article: Security Theater: Why "Easy Crypto for Foolish People" is Killing PGP

πŸ“ New article: Security Theater: Why "Easy Crypto for Foolish People" is Killing PGP

Scheduled Pinned Locked Moved Uncategorized
privacysecurityopensourcevirebent
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • virebent@mastodon.socialV This user is from outside of this forum
    virebent@mastodon.socialV This user is from outside of this forum
    virebent@mastodon.social
    wrote last edited by
    #1

    πŸ“ New article: Security Theater: Why "Easy Crypto for Foolish People" is Killing PGP

    How 'easy crypto' tools like FlowCrypt and Thunderbird's built-in PGP are fracturing OpenPGP standards, forcing security downgrades, and why NeoMutt with GnuPG remains the only sane choice.

    πŸ”— https://www.virebent.art/blog/EasyCryptoforFoolishPeople.html

    #privacy #security #opensource #virebent

    upofadown@mstdn.caU 1 Reply Last reply
    0
    • virebent@mastodon.socialV virebent@mastodon.social

      πŸ“ New article: Security Theater: Why "Easy Crypto for Foolish People" is Killing PGP

      How 'easy crypto' tools like FlowCrypt and Thunderbird's built-in PGP are fracturing OpenPGP standards, forcing security downgrades, and why NeoMutt with GnuPG remains the only sane choice.

      πŸ”— https://www.virebent.art/blog/EasyCryptoforFoolishPeople.html

      #privacy #security #opensource #virebent

      upofadown@mstdn.caU This user is from outside of this forum
      upofadown@mstdn.caU This user is from outside of this forum
      upofadown@mstdn.ca
      wrote last edited by
      #2

      @virebent A couple of comments.

      Assuming a good passphrase, it is perfectly OK to store your secret key information in a place that attackers can get to. The actual problem here is that most systems that use passphrases don't have good enough usability so that users can reliably create and use such a passphrase.

      AFAIK, OCB mode is for performance, not security. For something like email, good old OCFB-MDC mode is fine. Otherwise you subject the users to the stupid OpenPGP standards schism/war. Ironically, it appears that OCFB-MDC is actually more secure than at least one of the proposed new modes (GCM):

      Link Preview Image
      Principles of the OpenPGP SEIP (OCFB-MDC) and SE (OCFB) Block Cipher Modes [The Call of the Open Sidewalk]

      favicon

      (articles.59.ca)

      1 Reply Last reply
      1
      0
      • R relay@relay.mycrowd.ca shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups