TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Facebook and PGP

149 pointsby alexweberalmost 10 years ago

14 comments

michaeltalmost 10 years ago
Another possibility is one of their programmers thought "It would be good if there was more encrypted e-mail going around in general, I wonder if I can get it into facebook somehow" and coded this feature in their free time. Then convinced his managers to integrate it with that argument plus "and it's already coded we just need to merge it in"
评论 #9651234 未加载
评论 #9651314 未加载
评论 #9651794 未加载
alexbeckeralmost 10 years ago
To me the strangest thing about this announcement is that, while the PGP user base is small, I imagine its intersection with Facebook's is much, much smaller. PGP is used by people who are extremely concerned with privacy, which is practically the antithesis of Facebook.
评论 #9651085 未加载
评论 #9654844 未加载
评论 #9651664 未加载
评论 #9655029 未加载
p4bl0almost 10 years ago
The last paragraph of the linked post describes more or less what keybase [1] is.<p>[1] <a href="https:&#x2F;&#x2F;keybase.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;keybase.io&#x2F;</a>
评论 #9653567 未加载
评论 #9651211 未加载
pjbrunetalmost 10 years ago
Back in the Myspace era, I was bored and created an easy encoder-decoder for people to play with. It worked with Twitter, Facebook and Myspace (cut-paste your encoded text) because it only used basic characters. As you can&#x27;t see in this animation, I later added random spaces and punctuation to the encoded text so that theoretically it would be harder for social networks to detect and block. The text was encoded in Javascript as you typed, which I thought was cool :-)<p>You can see it here as a GIF animation <a href="http:&#x2F;&#x2F;pjbrunet.com&#x2F;friends-secret-messages.gif" rel="nofollow">http:&#x2F;&#x2F;pjbrunet.com&#x2F;friends-secret-messages.gif</a> The decoder was just as easy, another pink box under the encoder. Obviously a pro could crack the code but that wasn&#x27;t the point.<p>It was free. I advertised it to hundreds of thousands of people at the top of my blog which was 99% social media users and many of them were interested in privacy related topics as I could see from the Google queries. Looking at the CTR on that banner (asking people to try it) I concluded nobody cared. I was obviously targeting people who weren&#x27;t tech savvy. I had some friends try it, they said they felt like James Bond ;-) That particular app had no traction, but my &quot;pipe letter generator&quot; did much better.<p><pre><code> ╔╔╗════╔╗═╔╗═════╔╗═══════╔╗══════════════════╔═╗╗ ║║╚╗╔═╗║║═║║═╔═╗═║╚╗╔═╗╔═╗║╠╗╔═╗╔═╗═╔═╗╔═╗╔╦╦╗║═╣║ ║║║║║╚╣║╚╗║╚╗║║║═║║║║╬║║═╣║╦╣║╚╣║╔╝═║║║║╚╣║║║║╠═║║ ║╚╩╝╚═╝╚═╝╚═╝╚═╝═╚╩╝╚╩╝╚═╝╚╩╝╚═╝╚╝══╚╩╝╚═╝╚══╝╚═╝║ ╚════════════════════════════════════════════════╝</code></pre>
评论 #9651366 未加载
diminoalmost 10 years ago
What if Google validated PGP signatures for you from trusted, popular certs?<p>They&#x27;d have Facebook&#x27;s pubkey on file, and -- transparent to you -- would create something analogous to my browser&#x27;s lock icon in their email browser. Any time you got an email from Facebook, it&#x27;d say &quot;Verified Sender&quot;.<p>Heck, couldn&#x27;t we tie mail from Facebook back to their domain cert given to them by their CA? If it says @facebook.com, and it&#x27;s passes verification from the cert on facebook.com, then it&#x27;s actually from Facebook, right?
评论 #9651125 未加载
excel2flowalmost 10 years ago
Btw, does PGP support triple wrapping to prevent surreptitious forwarding? (S&#x2F;MIME does - <a href="https:&#x2F;&#x2F;www.ietf.org&#x2F;rfc&#x2F;rfc2634.txt" rel="nofollow">https:&#x2F;&#x2F;www.ietf.org&#x2F;rfc&#x2F;rfc2634.txt</a>)<p>I really don&#x27;t understand why it has been chosen over S&#x2F;MIME. Maybe they gave the money to that german guy who wrote it and now they don&#x27;t want them to be completely wasted :)
评论 #9651374 未加载
评论 #9651275 未加载
leejoramoalmost 10 years ago
Following Facebook&#x27;s story on PGP, I see I had missed that Facebook directly supported Tor since last fall. <a href="https:&#x2F;&#x2F;www.facebook.com&#x2F;notes&#x2F;protect-the-graph&#x2F;making-connections-to-facebook-more-secure&#x2F;1526085754298237" rel="nofollow">https:&#x2F;&#x2F;www.facebook.com&#x2F;notes&#x2F;protect-the-graph&#x2F;making-conn...</a>
hstraussalmost 10 years ago
I think the nicest part of this is that account recovery e-mails are encrypted. I wish we&#x27;d see more of this.<p>While I&#x27;m cautious about facebook in general, it is (in essence) a repository for public data. A public key falls into that category, so they gain nothing more than the association of user and key. And in return, the PRISM databank has more superbly useless information to store and eventually &#x27;collect&#x27; for 1EF communication.<p>And I gain immunity from account hijacking unless I mess up Key Management.
lmmalmost 10 years ago
Has anyone got an encrypted email from facebook yet? I uploaded my key and ticked the box, but the last notification I got was still in the clear.
评论 #9651573 未加载
评论 #9653875 未加载
golemotronalmost 10 years ago
The easy answer is that they knew Apple was going to come out strong for encryption in the past few days and wanted to do a &quot;me too.&quot;
评论 #9652215 未加载
评论 #9652845 未加载
评论 #9652077 未加载
anthony_barkeralmost 10 years ago
Private public keys + verification gives way to lots of uses...<p>Payments (bitcoin style currencies), banking, document signitures, and single sign-on?
评论 #9654510 未加载
rmorizalmost 10 years ago
I wish they had opted to use S&#x2F;MIME, because of the wide support in MUA and because it&#x27;s relatively easy use even for non geeks.<p>Some time ago I started collecting support of S&#x2F;MIME in products and companies: <a href="https:&#x2F;&#x2F;gist.github.com&#x2F;rmoriz&#x2F;5945400" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;rmoriz&#x2F;5945400</a>
thomasahlealmost 10 years ago
Regarding making this work with GMail, Google still has their End-to-End GPG plugin for Chrome+GMail: <a href="https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;end-to-end" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;end-to-end</a>
jaysoncenaalmost 10 years ago
I like the idea of linking certificates to facebook accounts