!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

186 Members
44 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
16 Jul 2021
@andi:kack.itandi-I am not defending GPG...13:49:05
@grahamc:nixos.org@grahamc:nixos.orgyeah13:49:09
@grahamc:nixos.org@grahamc:nixos.orgI'm trying to think about what my position is here :P13:49:20
@andi:kack.itandi-TPMs in systems like Windows or MacOS are probably something ~15 engineers at either company understand and maintain. None of the millions of users has knowledge about them to use BitLocker or FileVault.13:50:07
@grahamc:nixos.org@grahamc:nixos.orgyes!13:50:16
@grahamc:nixos.org@grahamc:nixos.org100%13:50:19
@andi:kack.itandi-With GPG everyone has some wrong assumption on how it works but it works somehow (most of the time?)13:50:27
@grahamc:nixos.org@grahamc:nixos.org

the complicated bad stuff of GPG that I hate is:

  1. people don't know how to use it safely
  2. it is easy to do something catastrophically bad
  3. the lifecycle of the keys is "I dunno whatever"
13:51:51
@andi:kack.itandi- Like I was asked what kind of file encryption we (day job) could use for exchanging sensitive documents with a partner... The partner proposed GPG because their enterprise security department says it is secure. Nothing else is acceptable as it hasn't been audited. Something like age wouldn't even be considered even if it is simpler and better suited for the process :/ 13:52:06
@andi:kack.itandi-And I think with "audited" they don't mean having read the GPG code...13:52:38
@grahamc:nixos.org@grahamc:nixos.orghahaha no chance13:52:43
@andi:kack.itandi-Hell, I'd probably propose just using openssl CLI instead of GPG...13:53:04
@grahamc:nixos.org@grahamc:nixos.orgoh and 4. people pretend like mere mortals could use it13:53:13
@grahamc:nixos.org@grahamc:nixos.orgat least with a TPM nobody is expecting regular people to actually interact with it13:53:33

Show newer messages


Back to Room ListRoom Version: 6