Home | Community | Message Board


This site includes paid links. Please support our sponsors.


Welcome to the Shroomery Message Board! You are experiencing a small sample of what the site has to offer. Please login or register to post messages and view our exclusive members-only content. You'll gain access to additional forums, file attachments, board customizations, encrypted private messages, and much more!

Unfolding Nature Shop: Unfolding Nature: Being in the Implicate Order

Jump to first unread post Pages: 1
supporter encryption question/feature request
    #26281864 -

i did save copy of private key when offered after upgrade to supporter, however, it cannot be imported locally (using openpgp encryption applet, dev by Tails team, iirc, relies on Seahorse). openpgp applet/seahorse errors stating keyfile is not recognizable. fwiw, I was able to decrypt msg by pointing at the d/l key file so at least that works fine (using Tor browser and need to do that each session tho :/

really want to put pgp public key in the profile field for such but cant extract it since i can't import it. prefer using the openpgp applet for encryption tasks anyway and sharing public key allows others that do use pgp/gpg to encrypt msgs to us regardless they are a supporter or not.

on feature request, please allow to upload locally generated openpgp standard public key half to shroomery. can this be done, website allows import of public key for all or implemented for supporters to be able to do?

Thanks for considering!

ps. and please do forgive my cross-post! admin delete would be appreciated for my initially posted request in supporter forum, two of three current views was me rereading the request for clarity after a day of no views as well as reopen thread to copy for paste here :shrug:
(it seems to be a slow/little used forum and my misunderstanding of its purpose had me post there. actually all three views may have been me rereading it :lol:


--------------------
See a mush cult pic you love? add it here: January 2020 PoM nominations thread! (up vote your faves to ensure they are included in final vote!). Community selected winner receives a 6mo Supporter account upgrade and/or other prizes from our awesome admin team!

Looking for something? Try Psilosopherr's Tek Compendium and pixelpopper's essentialzzz ForTheWin!

Be well, friend. Stay Strong and Beautiful, Always, and in All Ways~
Look Forward, Seek Truth, Find Real, Go Further~

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: TeaforTwo]
    #26295806 -

:sporedrop: 6 day no admin response bump :salute:

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: TeaforTwo] * 1
    #26295840 -

Hey, I'm sorry this got overlooked, thanks for giving it a bump!

We do offer a way for you to add your public key to your profile on the Shroomery. In your basic preferences there is a field for "PGP Public Key" where you can paste your public key's text. It will then be listed in your profile, and people can download it in .ASC format.

Decryption for secure private messages is performed server-side, so we need the ability to manage the associated keypairs. We can't offer the ability to import your own keypair because that would require sharing your private key with us. I hope that makes sense!

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: Ythan]
    #26295925 -

hi Ythan, thanks for responding~

I have seen the public key space to paste into, and want to do that however I can't extract my public key from the generated one backed up when made. Used kleopatra and seahorse to attempt import and use with openpgp applet, both error saying not openpgp format.

backup is certainly not .asc format, .txt file appears incorrect ending with == instead of =xxxx but does decrypt fine (tested on msg sent to another who never replied, wasn't sure if they could decrypt)

was an encryption enthusiast for a decade starting in late 90s. likely forgetting many things but not understanding how server side decrypts if secret key is not present, unless you made a hash of my passphrase(?) which i think would work.

oh wait, no, had to point to private key backed up on client side iot decrypt. how is that done, are you adding private key to site storage in browser, or a cookie or somesuch? (both those options sux for any using private browsing mode or Tor browser:/ it asks for private key backup every time after browser close

i imagine it may be a massive headache, bridge too far sort, but think one great example of client side generate or import your own openpgp standard public key/upload server side, is Startmail (from the Startpage search team), works well and allows for key revoke and new public key uploads.

otherwise how would we revoke or change key using system as is?

what is the server generated key expiration, algo and bit strength?

would you consider have public key half to auto-populate that form field in basic preferences? as it stands right now I have found no access to public key.


--------------------
See a mush cult pic you love? add it here: January 2020 PoM nominations thread! (up vote your faves to ensure they are included in final vote!). Community selected winner receives a 6mo Supporter account upgrade and/or other prizes from our awesome admin team!

Looking for something? Try Psilosopherr's Tek Compendium and pixelpopper's essentialzzz ForTheWin!

Be well, friend. Stay Strong and Beautiful, Always, and in All Ways~
Look Forward, Seek Truth, Find Real, Go Further~

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: TeaforTwo]
    #26296122 -

Hey, does this post address your questions?

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: Ythan]
    #26296701 -

no, not a single question answered. as well it confirms all my worst concerns and now consider provided encryption compromised and unusable as is.

i do not want to waste your time, one last hope question then i'll drop the issue as unsolvable using forum offered encryption and resort to posting my own public key and link in sig as naum did.

is there any way possible to get a copy of my supporter public key from Shroomery in .PKR or .ASC format?

if yes, please tell me how. Thanks!


--------------------
See a mush cult pic you love? add it here: January 2020 PoM nominations thread! (up vote your faves to ensure they are included in final vote!). Community selected winner receives a 6mo Supporter account upgrade and/or other prizes from our awesome admin team!

Looking for something? Try Psilosopherr's Tek Compendium and pixelpopper's essentialzzz ForTheWin!

Be well, friend. Stay Strong and Beautiful, Always, and in All Ways~
Look Forward, Seek Truth, Find Real, Go Further~

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: TeaforTwo]
    #26297352 -

Ythan has just offered a streamlined way for people to use encryption for the average user.

Best practice is to always manually handle your own encryption offsite using open source software that has been audited. In saying that for what we do here the site wide offers ok safety. Pasting you public key into your profile is the best way.

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: TeaforTwo]
    #26304991 -

I'm sorry, I must have misinterpreted your question because I thought that post would clarify most of your concerns. Please let me try again with a more thorough reading.

I have sent you your public key via PM but I'm not sure it will be good for much.

Key strength is 1024-bit DSA with no expiration.

We don't expose your public key because we never intended to offer a fully realized PGP client. We simply want to provide an improved baseline level of security for messages at rest, compared to the plaintext storage offered by most other forums.

As an encryption enthusiast for 20+ years, perhaps you can help elucidate the arguments for client-side encryption. Our secure PM system was created at a time when there were no good client-side solutions available, and we don't have any cryptographers on staff, so we used the available technology. However, there are now projects like OpenPGP.js which make client-side encryption feasible. While I am open to the possibility of integrating this functionality, my assertion is that it would offer no security benefit over our current server-side implementation. Indeed, my position is that any web-based PGP implementation will be inherently insecure. The reason for this is your browser loads and runs arbitrary code every time you use the encryption functionality anyway. There is no easy mechanism to audit the code yourself or verify its integrity against a trusted checksum. This presents a trivial opportunity to insert a backdoor. I cannot envision a single scenario where our secure PM implementation is vulnerable but a web-based client-side approach would not also be vulnerable to the same attack.

There's a difficult balance with making encryption secure but also easy enough that people actually use it. Eg. Signal vs. WhatsApp. We do our best and if you have any suggestions I'll be glad to consider them.

Extras: Filter Print Post Top
Re: supporter encryption question/feature request [Re: Ythan]
    #26305451 -

missed this reply, resolved in PM prior. wasn't meaning to sound braggy above, my enthusiasm time was a decade, begun late 90s and ended when i went to combat the results of which were life changing and even important things fell completely off the table afterwards. even when i do recall stuff from prior it is often rusty, dusty and none too trusty.

in response: there is no security benefit from 1024bit strength asymmetric encryption, it was considered compromised in 2002 and has been completely dead to the crypto world since 2010 (albeit still in use in places, like here). it is less than an envelope we mail personal letters in, it is more like an opaque film covering a postcard.

client side encryption is the only assurance one could have nowadays for data at rest and data in transit, requires no trust in any server nor routing, diligence against rogue scripts, like all malware, is on the user as it is and should be.

I do agree allowing it to be handled and managed by browser is bad idea and use trusted app, openpgp applet in my case (Tails team develop, uses seahorse backend) because of such concerns. which i do consider 'client side', albeit sans the 'automagic' stuff.

also mentioned startmail as an example above- they do openpgp operations server side, and also allow users to upload their own openpgp standard keys (was lacking in the ECC dept last i checked tho). Even having my private key block was not as concerning as my passphrase is over 128 bits of entropy.

same for my key made here, but why even break out the rubberhose to tickle out my passphrase when a couple PSIIIs could crack the encryption itself at 1024bit strength.

Thing is, who is the encrypted function designed to protect us users against?

Cloudflare (the original honeypot project guys turned save the world from DDOS attackers) already has access to every thing on this site that is behind their great firewall. no subpoena needed to get in here, just go talk to cf for the plaintext of everything (including decryption passphrases and the 1024bit secret keys themselves that need get uploaded if user logs out, or uses tor, or clears cache, etc. and it gets worse.. as it has been proven CF-Ray ID is unique to every access thru their firewall and that they do terminate encryption at their proxy to all sites they host.

That is straight up the best MITM attack ever designed and the entire world is providing much more lucrative info than ever imagined by the cia (or some tla) dude that first tickled their brains about the "real value" of data they had from the honeypot project. none of this is paranoid delusions of an insane maniac, cf states it themselves (except the MITM part, but that has been proven by smart guys.

Encrypted data at rest is awesome to offer, but at that strength, with no expiration, anyone with access now to database can make trivial work of it.

if subpoenaed then 'they' would likely thank server admin for making it so easy with the false sense of security many may have relied upon to keep real name, home address and personal infos preferred not readable by any other than who they chose to share it with safe forever and only readable by key owner (and whomever they provide copy/read the message to, sadly).

I do plan on trading and giving away prints, for microscopy use, as many have and do here. and believe there is little concern of a 'raid' or the bigs coming for us, currently and has been assumed in the past, not many operate at that threat level, certainly including me.

but the writing is on the wall as psilo is gaining traction on the medical use front and when (not if, imo) it gets rescheduled then big pockets will be filled quick, and greed only feeds itself by more greed, so the lawmakers and enforcers will be looking for any cheating the system of pay to play.

and that dont set well with me. idk what the statute of limitations will be like over such topic in the future, and if there will even be any 'grandfathering' for such laws involved.

if anything, please do upgrade from GnuPG v1. the enemy never sleeps and servers can be compromised, as you well know. dont give future attackers the keys to the castle if they get their foot in the door. and why make it simple for authorities to take what they want with proper docs in hand.

if it cant be upgraded, or not worth the time and effort, then do everyone a favor and shut it down because there is no security in it and maintaining as is lends to gross negligence towards user safety moreso than any seem willing to admit.

me? on min key strength, i do believe 256bit symmetric, as well ecc and 15k asymmetric equivalents to be safe for the foreseeable future (until quantum computing becomes a reality anyway). still, expiration dates should be no more than 3yrs and revoke keys must be generated at time of initial key gen (and uploaded/sent out if/when necessary). I believe in the web of trust and feel signing keys is a valid approach, even if inconvenient, with low risk being fine done over encrypted voice channels.

I believe OTP is and will remain safe. I believe there are very few trustworthy, but very good, E2EE chat apps out there, such as briar and tox/qtox and to lessor extent (when anonymity is desired at all) signal and wire.

i'll use shroomery server side encryption even, if it gets some love and becomes actually reliable and usable until then i'll use the pre-PM msg function to inform others if it is personal infos involved then encrypt using my public key in profile (which i'm currently generating) or for chat contact via tox ID put in another block.

I state clearly that none of this has had any negative effect on my genuine appreciation for you having given us this information wonderland over the past 2 decades and the incredible resource it truly is.

Thanks Ythan, for keeping it alive and keeping it real.


--------------------
See a mush cult pic you love? add it here: January 2020 PoM nominations thread! (up vote your faves to ensure they are included in final vote!). Community selected winner receives a 6mo Supporter account upgrade and/or other prizes from our awesome admin team!

Looking for something? Try Psilosopherr's Tek Compendium and pixelpopper's essentialzzz ForTheWin!

Be well, friend. Stay Strong and Beautiful, Always, and in All Ways~
Look Forward, Seek Truth, Find Real, Go Further~

Extras: Filter Print Post Top
Jump to top Pages: 1

Unfolding Nature Shop: Unfolding Nature: Being in the Implicate Order


Similar ThreadsPosterViewsRepliesLast post
* Feature Request: a DIY Self Ban button.
( 1 2 all )
AsanteM 1,877 25 01/18/21 02:30 PM
by PatrickKn
* question from OTD never answered
( 1 2 all )
Captain Jack 3,012 20 02/12/03 04:22 PM
by Senor_Doobie
* enhancement request - quick pm afoaf 2,154 15 06/11/03 09:06 AM
by afoaf
* Encryption on forums? roofus 1,186 5 11/16/03 09:20 PM
by automan
* search feature megaman3 1,548 11 03/17/03 05:59 PM
by Anno
* BB upgrade problems, questions? Post here.
( 1 2 3 4 all )
ThorA 12,127 69 01/22/03 12:34 PM
by goldtop
* New "Support Group Central" forum is open.
( 1 2 all )
YthanA 3,736 20 03/10/03 12:34 AM
by canid
* "Search All Forums" feature.... boxtop703 918 4 01/25/03 11:43 AM
by Andytweed

Extra information
You cannot start new topics / You cannot reply to topics
HTML is disabled / BBCode is enabled
Moderator: Ythan, Thor, Seuss, geokills
351 topic views. 0 members, 10 guests and 2 web crawlers are browsing this forum.
[ Show Images Only | Sort by Score | Print Topic ]
Search this thread:

Copyright 1997-2026 Mind Media. Some rights reserved.

Generated in 0.031 seconds spending 0.007 seconds on 17 queries.