Re: [Enigmail] Future OpenPGP Support in Thunderbird
Daniel Kahn Gillmor <[email protected]> Mon, 28 Oct 2019 12:28:36 -0400
| Newsgroups | gmane.comp.mozilla.enigmail.general |
|---|---|
| Message-ID | <[email protected]> |
On Sun 2019-10-27 21:40:07 -0400, Eli Schwartz wrote:
> I didn't say I don't want people to use keyservers. There is no
> "either" here. You don't want people to use keyservers. I want people
> to use keyservers, and I want GnuPG to fix its brokenness so people
> can use keyservers.
I also want GnuPG to fix its brokenness when encountering
dangerous/invalid material.
There are multiple things broken in the ecosystem here, and SKS is only
one of them. But while GnuPG's errors are implementation errors, SKS is
also broken *by design*, so we need to think about how to design better
keyserver protocols. (SKS also has implementation errors, fwiw)
We can think about all of these things at the same time.
And, frankly, keyservers *are* problematic, in several different ways,
abuse being just one of them.
> I would be thrilled if people with experience in developing GnuPG would
> respond to the situation by, I dunno, teaching GnuPG how to sanitize
> input before blindly loading said data into an exploding parser.
Have you followed the changes in the latest versions of GnuPG? There is
some much more significant sanitization done on certificates retrieved
from keyservers in 2.2.17.
I won't say i agree with all of those changes (i've actively changed
some of them in the version of GnuPG we distribute in debian, because
import-clean can lead to data loss, see https://dev.gnupg.org/T4628 for
details), but efforts to limit the damage that can come in from
keyservers are definitely under way.
> I'm curious: do you *also* feel the concerns of people who just want the
> Web of Trust to work reliably?
I definitely care about the network of identity assertions that people
call "web of trust". I'm not convinced that it has ever worked reliably
for most people or most use cases, unfortunately. i say that as a
Debian developer, one of the groups that is the most heavily invested in
the idea. I know Arch cares about it too.
I'd love for it to be more reliable than it has been in the past, and
getting that to happen requires fixing a lot of different pieces.
Please, help us get them fixed!
> Literally every single possible iota of messaging I've seen from
> anywhere in the OpenPGP community is "the world will suddenly be perfect
> if no one can attack *MY* key because of my Lord and Savior, hagrid". As
> far as I can tell, it's not just missing the point, it hasn't even found
> the continent where the point is hiding.
This sort of rhetoric seems like it just serves to alienate you from the
people who are doing the work to improve the community. I don't know
anyone who thinks this, not even the folks who operate hagrid. If this
is an attempt to characterize my position, it's rather inaccurate.
There's a pretty broad consensus that tools should validate input, and
that GnuPG needs to take more serious steps than it has in the past to
defend against potentially malicious inputs.
Part of this work involves understanding the incentives and risks that
apply to the rest of the ecosystem, which might make them publish data
that is different from data that they've published in the past, and
helping GnuPG figure out how to handle that data.
Or, helping other OpenPGP implementations that aren't GnuPG become
easier to use, so that people can move to a different implementation if
they don't think that GnuPG takes these concerns as seriously as they'd
like it to.
I welcome your help in getting these things fixed!
All the best,
--dkg
_______________________________________________
enigmail-users mailing list
[email protected]
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net
signature.asc
(application/pgp-signature, 227 B)
-----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQTJDm02IAobkioVCed2GBllKa5f+AUCXbcXNAAKCRB2GBllKa5f +F+YAQCpp9ldED15+/8Z2nH1y6i0sIzo39edbSo0Gc3RPTNRPAD9FuS0dKfvXli6 LlwFEf2NOJWwg355P4iV3fM4OOTpZwQ= =DBNJ -----END PGP SIGNATURE-----