Hacker News new | ask | show | jobs
by sk5t 2788 days ago
You seem to be inferring focus on the name of the company more than intended. Is this not closed-source software? Might not it have some weaknesses at any point in its implementation or update mechanisms--by design or inadvertent--that put it at a disadvantage to PGP?
1 comments

This discussion started because someone claimed that the crypto of one was superior the crypto of the other, the implementations aren't strictly relevant i.e.:

> anyone with even a basic understanding of crypto would do things the other way around.

Not least of all because they made no reference to which implementation of PGP they were even calling superior, only the protocol itself.

The choice isn't between using OTR vs. using PGP. It's between using unaudited (but perhaps convenient) commercial software vs. using possibly-audited, offline-friendly (probably inconvenient) PGP to exchange extremely-high-sensitivity messages. The apocryphal Snowden account even appears to suggest PGP for the lower-sensitivity message.