Re: Do you use PGP encrypted email with Roundup (potential removal)?
Bernhard Reiter via Roundup-users <[email protected]> Thu, 21 Nov 2024 09:48:57 +0100
| Newsgroups | gmane.comp.bug-tracking.roundup.user |
|---|---|
| Message-ID | <[email protected]> |
--===============5509406160626033447==
Content-Type: multipart/signed;
boundary="nextPart11628299.eudtdsMapo";
protocol="application/pgp-signature";
micalg=pgp-sha1
Content-Transfer-Encoding: 7bit
--nextPart11628299.eudtdsMapo
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline
Hi John,
Am Samstag 16 November 2024 17:53:11 schrieb John P. Rouillard:
> I am looking at the future of support for PGP encrypted email.
>
> Does anybody (still) use PGP encrypted email?
yes, increasingly so.
It got a lot easier with the web key directory.
(https://wiki.gnupg.org/WKD)
> For those that don't know, you can sign/verify email sent to Roundup
> by enrolling user's public keys. I think the intent was to validate
> commands and changes sent on the subject line of an email. It can
> also encrypt outgoing PGP emails, but it has issues (issue2550943,
> issue2550942).
OpenPGP increases the confidentiallity and integrity back and forth
to email usage with roundup. When we use roundup to track contracts
with customers that are security aware, it is a huge plus.
(And makes up a bit for other shortcomings of roundup.)
It is also about messages and their contents, not just about status command=
s.=20
You do not want to have messages from somebody (with forged sender address)
in your tracker, e.g. saying okay or not to somethings.
> As far as I can tell it was never well documented. After much struggle
> a while ago I managed to get it to work, but I still wasn't able to
> document a working process. Also sending PGP encrypted email was not
> exactly straightforward.
>
> Before Roundup 1.5, tracker auditors did not even know the source of
> the transaction. tx_Source was added to support "email" and
> "email-sig-openpgp". Before then, you had to use PGP for all email
> from a user. PGP had to be used even if they weren't doing something
> that required authentication/authorization. Otherwise you were
> vulnerable to forged email.
Adding a message also needs authentication.
> Also articles such as:
>
> https://www.latacora.com/blog/2019/07/16/the-pgp-problem/
that criticism is quite unbalanced and in parts not considering aspects tha=
t=20
were known at the time. Three examples:
1. UX: does not consider advances by WKD (which is from 2016).
2. No Forward Secrecy: Not possible with aysychronuos systems.
3. The efail disclosure: Was handled fine by GnuPG (*)
Read https://gpg4win.org/statement-efail.html
and https://gpg4win.org/statement-spoofing.html
And then they recommend: Use [..] or WhatsApp [..]
As this are central and online communication systems, they have massive=20
drawbacks. Email is decentral and multi "vendor" - one of the only working=
=20
systems there is. (Another one would be XMPP, which is geared to less=20
structured data.)
(*) To be clear: I am with the GnuPG team for more than 20 years, but=20
security needs sound reasoning. So if time permits, I read and consider=20
arguments. However:
> https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/
Is based on the above article and states:
> Not to mince words: The same people who believe PGP is good are also=20
famously not great at cryptography engineering.
:/ While the graphics are great, the reasoning does not seem to be
and it starts claiming that my reasoning is "famously" wrong,
not a good start.
> make me reconsider PGP support. Some of the problems discussed above
> don't apply to Roundup's use of PGP. But the overall impression is not
> favorable.
OpenPGP v4 is one of two widely spread standards
of the only working decentral, asynchronous communication standard.
The other is based on the "cryptographic message syntax" (CMS) and uses the=
=20
X509, PKI line of work, and email would be in S/MIME format.
Other interoperable multi vendor systems would be the short messages service
of mobile phones. But that is online and not end-to-end encrypted.
> Wgat bring this to the front is that I can't build a working PGP
> toolchain in Python for our continuous integration platform. See:
> https://issues.roundup-tracker.org/issue2551368. This means PGP code
> won't be tested unless done locally by a developer.
I'll look into that if I can. That for the note.
> My thoughts are that PGP was useful in earlier days (2000-2010) when
> internet connectivity wasn't as easy, but is not so useful today.
The need for end-to-end crypto seems as high, if not higher than before.=20
Especially with more internet infrastucture providers or companies having a=
=20
reason to listen.
> My plan at this point is:
>
> * announce that PGP support will be included but not tested for
> Roundup 2.5.
>
> * if a tracker has pgp support enabled, 2.5 will print a warning
> when starting up.
>
> * remove the PGP code in release 2.6.
>
> Does anybody currently use PGP for tracker emails? If so are you
> willing to handle maintenance/documentation of this subsystem and
> resolve issues?
Yes, yes.
> More generally, does a method for:
>
> * verifying the sender and contents of email
> * encrypting sent emails
>
> still have value?=20
Yes.
> If so=20
> https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/ lists a
> couple of ideas (e.g. encrypted/signed attachment).
The author is working on "something better". Maybe this explains the=20
polarizing view taken in the article to some extend. However it is fine to=
=20
work on new solutions and try to do things better. Email end-to-end crypto=
=20
based on OpenPGP or CMS stays relevant in working contexts though.
Browsing the article there is no real new idea for a tracker's use case. Us=
ing=20
a messenger like signal or threema over email could be an additional featur=
e,
but again I do not see that in organisational contexts. And the task of=20
verifying the identity is even less well solved for Signal than in a well=20
maintained OpenPGP or CMS environment.
Best Regards,
Bernhard
=2D-=20
https://intevation.de/~bernhard =A0 +49 541 33 508 3-3
Intevation GmbH, Osnabr=FCck, DE; Amtsgericht Osnabr=FCck, HRB 18998
Gesch=E4ftsf=FChrer: Frank Koormann, Bernhard Reiter
--nextPart11628299.eudtdsMapo
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part.
-----BEGIN PGP SIGNATURE-----
iQGzBAABCgAdFiEEvdlX+cT+D9xYPc1tK3ujv5vDpVQFAmc+8/oACgkQK3ujv5vD
pVRWNAwApLRdYSxQ+2NrfrCwwgS4uQtYbpGHRVwAUWtHVcz31wZ399slPbVPey5A
rpuX8HpwazlZvoInFAOMoSbgRKM39sEuADLWP3e/pKxaDoLjO/q0sfZYB3w000K9
ggmOc4b8gYdCCj5fnzG42u724pRkD5oO3Ez0kfwWZVIt4jLxPvIT4tRBXsmTAgGb
e3+z/r2ig1Fy35vjBq0pSVo7u+YNd4KPX1PHtrN4fHSG/mS+5gX5avOcLvsNCwpL
j2FwQt6nuXv6lXYfO32ZNQyOI1mD24nloYnpODEEaPnJIEPUK3YPVAI+UvkRepda
Sk+iR19v0baPNUVHzY4s/zxTdgucTiTA+YxpDTqzSLvtfLoh6aYx8XhoRh/Iy6z4
LecAWDoP3642rwbU2jy1MC+vTgw5iwIR0Owd3HYyDdYeUL6a/YuMUU2Y/+0MxPce
ZOzS1baYwYZZzwTgnP8iW1nFZ8vC3YhV6KDMnNp4gOjlDbWKnfgJ9diPA1aladgn
z7Fh0q3w
=S1Ur
-----END PGP SIGNATURE-----
--nextPart11628299.eudtdsMapo--
--===============5509406160626033447==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============5509406160626033447==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Roundup-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/roundup-users
--===============5509406160626033447==--