SoK: Why Johnny Can't Fix PGP Standardization

08/16/2020
by   Harry Halpin, et al.
0

Pretty Good Privacy (PGP) has long been the primary IETF standard for encrypting email, but suffers from widespread usability and security problems that have limited its adoption. As time has marched on, the underlying cryptographic protocol has fallen out of date insofar as PGP is unauthenticated on a per message basis and compresses before encryption. There have been an increasing number of attacks on the increasingly outdated primitives and complex clients used by the PGP eco-system. However, attempts to update the OpenPGP standard have failed at the IETF except for adding modern cryptographic primitives. Outside of official standardization, Autocrypt is a "bottom-up" community attempt to fix PGP, but still falls victim to attacks on PGP involving authentication. The core reason for the inability to "fix" PGP is the lack of a simple AEAD interface which in turn requires a decentralized public key infrastructure to work with email. Yet even if standards like MLS replace PGP, the deployment of a decentralized PKI remains an open issue.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/22/2021

Statistical Analysis of ReRAM-PUF based Keyless Encryption Protocol Against Frequency Analysis Attack

There has been a growing interest in fully integrating Physical Unclonab...
research
06/23/2023

Preventing EFail Attacks with Client-Side WebAssembly: The Case of Swiss Post's IncaMail

Traditional email encryption schemes are vulnerable to EFail attacks, wh...
research
04/16/2019

Re: What's Up Johnny? -- Covert Content Attacks on Email End-to-End Encryption

We show practical attacks against OpenPGP and S/MIME encryption and digi...
research
08/04/2022

Identity-Based Authentication for On-Demand Charging of Electric Vehicles

Dynamic wireless power transfer provides means for charging Electric Veh...
research
07/13/2021

PakeMail: authentication and key management in decentralized secure email and messaging via PAKE

We propose the use of PAKE for achieving and enhancing entity authentica...
research
04/15/2019

IoD-Crypt: A Lightweight Cryptographic Framework for Internet of Drones

Internet of Drones (IoD) is expected to play a central role in many civi...
research
10/05/2021

Notarial timestamps savings in logs management via Merkle trees and Key Derivation Functions

Nowadays log files handling imposes to ISPs (intended in their widest sc...

Please sign up or login with your details

Forgot password? Click here to reset