Hacker News new | ask | show | jobs
by c0rrupted 1115 days ago
OpenPGP is pretty good, I don't get why it gets criticism to be honest. It even has support for quantum resistant cryptography now if I recall correctly. It's also pretty easy to use. OpenKeyChain for Android works great. So does Kleopatra on Linux. Even thunderbird has support for it
1 comments

I recently came along this post [0], which pretty much killed PGP for me. I certainly cannot follow all technical detail in the post, but I do see that cryptography has moved on and now offers e.g. forward secrecy.

[0] https://latacora.micro.blog/2019/07/16/the-pgp-problem.html

I should add that some of the risks mentioned in that post can be mitigated by proper user behavior (use a sufficient key length, limit the lifetime of your key). But then PGP is sufficiently complex and error prone (in using it and apparently in its technical complexity), that I don’t believe that it scales to everyone and their grandma using it.
I found the "The PGP Problem" fairly misleading:

* https://articles.59.ca/doku.php?id=pgpfan:tpp

Who would want to immediately destroy their access to their received emails in the name of forward secrecy?