Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You forgot about signatures, which TLS does not provide. Nor does Signal. (In a meaningful manual way.)

PGP and S/MIME do. The latter is used for all sorts of official messages for exactly that reason.

Unauthenticated encryption is rather worthless. Repudiation is a separate matter and threat model.



Sure! Use minisign/signify, and see OpenBSD for an example of people who do this who care extremely deeply about non-repudiation.


fwiw keybase supports simple and easy signatures (and less verbose than PGP.) combined with an (imo) much more rational and discoverable attestation of identity, I think it's nearly ready to supplant PGP for this use case. email integration for signatures would indeed be nice.


> Unauthenticated encryption is rather worthless

How so?

Mind you, unauthenticated encryption in terms of signal does not mean that anyone can forge a message, rather that you can't prove to a 3rd party that this was a message sent by the sender rather than forged by you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: