This is a good read. I think it’s a good solution if it can be implemented properly. Are there applications you know of that allow you to personally (manually) encrypt text and communicate with another person like GPG does?
You should not be doing manual communications as that opens the door for human error and is time consuming. Also these cryptography protocols are far to complex to easily be used for text.
And using these apps is not always an option. I like simplex, but sometimes email is one of the only options. PGP can be used agnostic of the technology used for transmission, and that’s exactly what we need to keep more people private instead of forcing them into a few select applications. If Diffie-Helman can be used in a transport-agnostic fashion then I do not see much progress in this direction.
Shared key??? PGP works on a public-private key-pair, and unless you’re giving out your private key, it’s not shared with anyone. This is blatant misinformation
The public key is public and there is a single vulnerable private key. Someone can identify you with the use of your public key and if someone gets access to your private key (maybe a solen device) they can decrypt logged messages that used that key. This means they can still get access even if you deleted the messages off your device.
That is indeed a disadvantage of PGP. Unfortunately, it is the most portable method of encryption text at rest at the moment. The moment somebody manages to figure out a way to use the Diffie-Hellman algorithm in a portable manner, I’m sure a lot of people will consider that a viable alternative. Till then, learn about disk encryption to keep your keys safe
https://en.m.wikipedia.org/wiki/Signal_Protocol
https://en.m.wikipedia.org/wiki/Double_Ratchet_Algorithm
https://en.m.wikipedia.org/wiki/Elliptic-curve_Diffie–Hellman
The signal protocol works on double ratchet that works on Diffie Hellman
This is a good read. I think it’s a good solution if it can be implemented properly. Are there applications you know of that allow you to personally (manually) encrypt text and communicate with another person like GPG does?
https://simplex.chat/
https://signal.org/
You should not be doing manual communications as that opens the door for human error and is time consuming. Also these cryptography protocols are far to complex to easily be used for text.
And using these apps is not always an option. I like simplex, but sometimes email is one of the only options. PGP can be used agnostic of the technology used for transmission, and that’s exactly what we need to keep more people private instead of forcing them into a few select applications. If Diffie-Helman can be used in a transport-agnostic fashion then I do not see much progress in this direction.
Just keep in mind PGP is weaker in the sense that it is easier to break due to its shared key.
Email itself is not exactly a secure protocol
Shared key??? PGP works on a public-private key-pair, and unless you’re giving out your private key, it’s not shared with anyone. This is blatant misinformation
The public key is public and there is a single vulnerable private key. Someone can identify you with the use of your public key and if someone gets access to your private key (maybe a solen device) they can decrypt logged messages that used that key. This means they can still get access even if you deleted the messages off your device.
That is indeed a disadvantage of PGP. Unfortunately, it is the most portable method of encryption text at rest at the moment. The moment somebody manages to figure out a way to use the Diffie-Hellman algorithm in a portable manner, I’m sure a lot of people will consider that a viable alternative. Till then, learn about disk encryption to keep your keys safe