Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  > Actually it is a feature.
There's a critical flaw in PGP actually. If you reply to any PGP encrypted email with "sorry, I couldn't decrypt" you'll, with high likelihood, get the cleartext version of the email soon after.

The joke is quite old and part of what I'm pointing to. Security doesn't work well if it isn't very usable. At least this is a bit better than secure communication, but it isn't as huge of a difference as it might appear.

The biggest boon in security has come due to making these tools easy to use. That's from decades of experience is realizing you can't get everyone to be technical.



> There's a critical flaw in PGP actually.

Passkeys use FIDO2, not PGP?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: