We're calling it: PGP is dead (2024)

But even before this week’s news, questions have been raised about the usability of PGP. Matthew Green, a cryptographer and professor at John Hopkins University has argued that “it’s time for PGP to die”. It turns out that for the majority of people, Pretty Good Privacy may not be good enough.

‘It’s time for PGP to die’

One of the many problems with PGP is its age, says Green. It was first developed in 1991 (“when we didn’t really know anything about crypto”) and then standardised into OpenPGP from 1997.

The science of cryptography has advanced dramatically since then, but PGP hasn’t, and any new implementations have to remain compatible with the features of previous tools, which can leave them vulnerable to similar exploits.

There are other faults, including the difficulty of accessing encrypted emails across multiple devices, and the issue of forward secrecy, which means that a breach potentially opens up all your past communication (unless you change your keys regularly). It’s rumoured that the NSA stockpiles encrypted messages in the hope of gaining access to the keys at a later date.

But the biggest problem with PGP is how difficult it is for people to use simply. "It’s a real pain," says Green. "There’s key management – you have to use it in your existing email client, and then you have to download keys, and then there’s this whole third issue of making sure they’re the right keys."

This criticism has plagued PGP for most of its existence. A technical research paper by Alma Whitten and JD Tygar called Why Johnny Can’t Encrypt: a Usability Evaluation of PGP 5.0 drew attention to the problem as early as 1999.

To encrypt an email manually using PGP requires a decent level of technical knowledge, and adds several steps to the process of sending each message, to the extent that even Phil Zimmerman, the creator of PGP, no longer uses it.

Read more: Protect your iPhone with these essential iOS security tips

“All of these things have been really hard for non-experts, and even for experts,” says Green. Even Edward Snowden has screwed it up. When he first reached out anonymously to a friend of Poitras, Micah Lee, to ask him for her public PGP key, he forgot to attach his own public key, meaning that Hill had no secure way to respond to him.

Many of the issues around PGP are aligned with email being a dated form of communication. To make PGP easier to use, end users can install plug-ins for their email clients, or use browser-based solutions to encrypt and decode their messages, but this is where vulnerabilities can creep in.

In the case of EFail, the issue is not with the PGP protocol itself, but with the way it has been implemented, says Josh Boehm, founder and CEO of encrypted communications service cyph.com, which offers private voice and video chat in a web browser.

“There’s no standard way of implementing it, so a number of people have just done it wrong,” he says. “That then becomes the weakest link in the chain. It doesn’t matter how strong the chain of PGP is, if they can get you to unlock it and send that information to them it’s essentially worthless.”

The rise of encrypted messengers

We could all benefit from end-to-end encryption of our emails, but because it’s so difficult to use, PGP has largely remained the reserve of tech-savvy whistle-blowers and cryptography experts. Green says a recent search puts the number of non-expired public PGP keys at around 50,000. “That’s the total usage of PGP,” he says. “The vast majority of people don’t use it.”

By contrast, in 2016, there were almost 50 million global downloads of the encrypted messaging app Telegram. On Twitter, links to PGP keys in the bios of journalists are being replaced by the phone numbers they use for Signal, the encrypted messaging service endorsed by leading security experts around the world. Then there’s Apple’s iMessage, and of course WhatsApp - which, in turning on end-to-end encryption for more than a billion by default has arguably done the most to take encryption to the masses.

We're calling it: PGP is dead (2024)

FAQs

What does PGP mean? ›

Pretty Good Privacy Definition. Pretty Good Privacy (PGP) is a security program used to decrypt and encrypt email and authenticate email messages through digital signatures and file encryption. PGP was first designed and developed in 1991 by Paul Zimmerman, a political activist.

Has PGP encryption been broken? ›

PGP encryption is almost impossible to hack. That's why it's still used by entities that send and receive sensitive information, such as journalists and hacktivists. Though PGP encryption cannot be hacked, OpenPGP does have a vulnerability that disrupts PGP encrypted messages when exploited.

Does anyone still use PGP? ›

Yes, PGP encryption is still used and is considered an industry standard for protecting sensitive information. Both commercial and free, open-source implementations of PGP are available. Commercial solutions offer technical support that may be lacking in freeware tools.

How do I unlock PGP messages? ›

Decrypt messages

Open the PGP Tray. Select Current Window. Choose Decrypt & Verify. Enter a passphrase into the PGP Enter Passphrase dialog box.

What does the term PGP refer to? ›

Pretty Good Privacy (PGP) is an encryption program that provides cryptographic privacy and authentication for data communication. PGP is used for signing, encrypting, and decrypting texts, e-mails, files, directories, and whole disk partitions and to increase the security of e-mail communications.

How serious is PGP? ›

PGP is not harmful to your baby, but it can be painful and make it hard to get around. Women with PGP may feel pain: over the pubic bone at the front in the centre, roughly level with your hips. across 1 or both sides of your lower back.

Is PGP illegal? ›

PGP was not exactly banned but if you were in Europe when ITAR restricted its export, and you were trying to download from strait-laced corporate types like AOL, they wouldn't let you.

How do I check my PGP encryption? ›

Signed messages received by API Gateway can be verified by validating the signature using the public PGP key of the message signer. PGP decryption and verification require two different keys: your own private key for decryption, and the sender's public key for verification.

What replaces PGP? ›

Virtru End-to-End Encryption –Better than Pretty Good

Virtru overcomes inherent weaknesses in PGP and S/MIME and represents the next generation of end-to-end encryption. “Virtru offers encryption as secure as PGP but makes it easy enough that our end users, customers and partners can use it regularly.”

Does Gmail use a PGP? ›

Use manual PGP/GPG encryption for Gmail

In order to manually do Gmail PGP encryption for your emails, you'll need to download a PGP or GPG software program to your local device. If you have Windows as your operating system, a good option is GPG4Win.

Has PGP ever been cracked? ›

In short, it is essentially impossible for anyone – be they a hacker or even the NSA – to break PGP encryption. Though there have been some news stories that point out security flaws in some implementations of PGP, such as the Efail vulnerability, it's important to recognize that PGP itself is still very secure.

Is PGP better than TLS? ›

While SMTP TLS offers transparent encryption, it only does so part of the way. PGP and S/MIME also leave gaps in their security, so those with a high-risk level are often better off combining these technologies. PGP can be difficult to use but is also the most flexible.

How do I fix blocked PGP messages? ›

Resolution
  1. Stop the PGP services by clicking the PGP Tray icon and selecting Exit PGP Services. ...
  2. Browse to the PGP Corporation > PGP folder in the user's profile. ...
  3. Right-click the PGPprefs. ...
  4. Add the following entry to the PGPprefs.xml file: ...
  5. Click File > Save.
  6. Close Wordpad.
Jul 19, 2024

What is the secret key in PGP encryption? ›

PGP then creates a session key, which is a one-time-only secret key. This key is a random number generated from the random movements of your mouse and the keystrokes you type. This session key works with a very secure, fast conventional encryption algorithm to encrypt the plaintext; the result is ciphertext.

Can you decrypt a PGP with a public key? ›

Decrypting a File

You should have already created a PGP key pair and provided the public key to your trading partner. You will use the private key from that key pair to decrypt incoming files from that same trading partner. Create a new Project and add the PGP Decrypt task to the Project Outline.

What does PGP mean in pregnancy? ›

Pelvic girdle pain (PGP) is pain which is felt around the pelvic joints, lower back, hips and thighs. Around 1 in 4 pregnant women experience PGP. The Pelvic Girdle. It can vary from mild to severe. The symptoms can be different for each person.

What does PGP mean in school? ›

Professional Growth Plans (PGPs) are job-embedded, self-directed professional development. In a PGP, educators set their own goals, align them to certification standards, design an action plan, and collect evidence documenting their growth towards achieving their goals.

What is PGP in the body? ›

The pelvic girdle is a ring of bones around your body at the base of your spine. PGP is pain in the front and/or the back of your pelvis that can also affect other areas such as the hips or thighs. It can affect the sacroiliac joints at the back and/or the symphysis pubis joint at the front.

What is PGP in healthcare? ›

Physician Group Practice (PGP) refers to a healthcare provider organization in which physicians are organized around their collective capacity to deliver a broad range of medical services.

Top Articles
BEL Share Price Target 2024-2030 Fundamentals & Quarterly Results - MSSV
Using Quizzes for practice and assessment
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Kieth Sipes

Last Updated:

Views: 6248

Rating: 4.7 / 5 (67 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Kieth Sipes

Birthday: 2001-04-14

Address: Suite 492 62479 Champlin Loop, South Catrice, MS 57271

Phone: +9663362133320

Job: District Sales Analyst

Hobby: Digital arts, Dance, Ghost hunting, Worldbuilding, Kayaking, Table tennis, 3D printing

Introduction: My name is Kieth Sipes, I am a zany, rich, courageous, powerful, faithful, jolly, excited person who loves writing and wants to share my knowledge and understanding with you.