missed this reply, resolved in PM prior. wasn't meaning to sound braggy above, my enthusiasm time was a decade, begun late 90s and ended when i went to combat the results of which were life changing and even important things fell completely off the table afterwards. even when i do recall stuff from prior it is often rusty, dusty and none too trusty.
in response: there is no security benefit from 1024bit strength asymmetric encryption, it was considered compromised in 2002 and has been completely dead to the crypto world since 2010 (albeit still in use in places, like here). it is less than an envelope we mail personal letters in, it is more like an opaque film covering a postcard.
client side encryption is the only assurance one could have nowadays for data at rest and data in transit, requires no trust in any server nor routing, diligence against rogue scripts, like all malware, is on the user as it is and should be.
I do agree allowing it to be handled and managed by browser is bad idea and use trusted app, openpgp applet in my case (Tails team develop, uses seahorse backend) because of such concerns. which i do consider 'client side', albeit sans the 'automagic' stuff.
also mentioned startmail as an example above- they do openpgp operations server side, and also allow users to upload their own openpgp standard keys (was lacking in the ECC dept last i checked tho). Even having my private key block was not as concerning as my passphrase is over 128 bits of entropy.
same for my key made here, but why even break out the rubberhose to tickle out my passphrase when a couple PSIIIs could crack the encryption itself at 1024bit strength.
Thing is, who is the encrypted function designed to protect us users against?
Cloudflare (the original honeypot project guys turned save the world from DDOS attackers) already has access to every thing on this site that is behind their great firewall. no subpoena needed to get in here, just go talk to cf for the plaintext of everything (including decryption passphrases and the 1024bit secret keys themselves that need get uploaded if user logs out, or uses tor, or clears cache, etc. and it gets worse.. as it has been proven CF-Ray ID is unique to every access thru their firewall and that they do terminate encryption at their proxy to all sites they host.
That is straight up the best MITM attack ever designed and the entire world is providing much more lucrative info than ever imagined by the cia (or some tla) dude that first tickled their brains about the "real value" of data they had from the honeypot project. none of this is paranoid delusions of an insane maniac, cf states it themselves (except the MITM part, but that has been proven by smart guys.
Encrypted data at rest is awesome to offer, but at that strength, with no expiration, anyone with access now to database can make trivial work of it.
if subpoenaed then 'they' would likely thank server admin for making it so easy with the false sense of security many may have relied upon to keep real name, home address and personal infos preferred not readable by any other than who they chose to share it with safe forever and only readable by key owner (and whomever they provide copy/read the message to, sadly).
I do plan on trading and giving away prints, for microscopy use, as many have and do here. and believe there is little concern of a 'raid' or the bigs coming for us, currently and has been assumed in the past, not many operate at that threat level, certainly including me.
but the writing is on the wall as psilo is gaining traction on the medical use front and when (not if, imo) it gets rescheduled then big pockets will be filled quick, and greed only feeds itself by more greed, so the lawmakers and enforcers will be looking for any cheating the system of pay to play.
and that dont set well with me. idk what the statute of limitations will be like over such topic in the future, and if there will even be any 'grandfathering' for such laws involved.
if anything, please do upgrade from GnuPG v1. the enemy never sleeps and servers can be compromised, as you well know. dont give future attackers the keys to the castle if they get their foot in the door. and why make it simple for authorities to take what they want with proper docs in hand.
if it cant be upgraded, or not worth the time and effort, then do everyone a favor and shut it down because there is no security in it and maintaining as is lends to gross negligence towards user safety moreso than any seem willing to admit.
me? on min key strength, i do believe 256bit symmetric, as well ecc and 15k asymmetric equivalents to be safe for the foreseeable future (until quantum computing becomes a reality anyway). still, expiration dates should be no more than 3yrs and revoke keys must be generated at time of initial key gen (and uploaded/sent out if/when necessary). I believe in the web of trust and feel signing keys is a valid approach, even if inconvenient, with low risk being fine done over encrypted voice channels.
I believe OTP is and will remain safe. I believe there are very few trustworthy, but very good, E2EE chat apps out there, such as briar and tox/qtox and to lessor extent (when anonymity is desired at all) signal and wire.
i'll use shroomery server side encryption even, if it gets some love and becomes actually reliable and usable until then i'll use the pre-PM msg function to inform others if it is personal infos involved then encrypt using my public key in profile (which i'm currently generating) or for chat contact via tox ID put in another block.
I state clearly that none of this has had any negative effect on my genuine appreciation for you having given us this information wonderland over the past 2 decades and the incredible resource it truly is.
Thanks Ythan, for keeping it alive and keeping it real.
-------------------- See a mush cult pic you love? add it here: January 2020 PoM nominations thread! (up vote your faves to ensure they are included in final vote!). Community selected winner receives a 6mo Supporter account upgrade and/or other prizes from our awesome admin team!
Looking for something? Try Psilosopherr's Tek Compendium and pixelpopper's essentialzzz ForTheWin!
Be well, friend. Stay Strong and Beautiful, Always, and in All Ways~
Look Forward, Seek Truth, Find Real, Go Further~
|