Idk if this is the right community for this conversation, but it’s been on my mind and I want to share it with someone.

In the 00’s every new thing we heard about the internet was exciting. There were new protocols, new ways to communicate, new ways to share files, new ways to find each other. Every time we heard anything new about the internet, it was always progress.

That lasted into the early teens and then things started changing. Things started stagnating. Now we’re well into the phase where every new piece of news we hear is negative. New legislations, new privacy intrusions, new restrictions, new technologies to lock content away and keep us from sharing, or seeing the content we were looking for. New ways to force ads.

At one point the Internet was my most favorite thing in the world. Now I don’t know if I even like it anymore. I certainly don’t look forward to hearing news about it. It’s sad, man. We’ve lost a lot. The mega corps took the internet from us, changed it from a million small sites that people created because they had big ideas, or were passionate about small ones, and turned it into a few enormous sites with no new ideas, no passion, just an insatiable desire for money.

We’re at the end of an era, and unlike the last 20 years of progress, I don’t think most of us will like what the next era brings.

  • @duncesplayed
    link
    English
    2
    edit-2
    10 months ago

    PGP itself is a bit of mess.

    For one thing, there’s really only one major/popular implementation of it these days, which is GPG. The codebase is arcane. Pretty major security vulnerabilities pop up constantly. It doesn’t have stable funding. Several years ago the entire project almost collapsed when the world discovered it had been maintained for several years by a single person who didn’t have any time or money to maintain it. The situation is a little bit better now, but not much.

    (For this reason, people are starting to use age instead of gpg, as the code is much smaller, cleaner, forces safe defaults, and doesn’t seem to have security problems)

    But the bigger problem that was never properly solved with PGP is key distribution. How do you get somebody’s key in the first place? Some people put their keys on their own personal (https) webpage, which is fine, but that’s not a solution for everyone, and doesn’t scale very well. Okay, so you might use a key server, but that has privacy implications (your identity is essentially public to the world) and centralizes everything down to a handful of small “trusted” key servers (since there would be no way to trust key servers in a decentralized way). We should probably just have email servers themselves serve keys somehow, but nobody’s put that into the email standard protocols.

    The fact that keys expire amplifies all the problems with key distribution, and encourages people to do really unsafe things with keys, like just blindly trust them. You can sign other people’s keys for them, but that also does not scale very well.

    The key distribution problem is something that things like Signal have “solved” with things like phone number verification, but there’s really no clear way to solve it on something totally distributed like email.