Recommended Posts

So I'm just trying to educate myself and can't seem to find an answer online.  I have my wife's public PGP key imported onto my laptop, but not her private key.  If I encrypt a file with her public key, in theory, nobody should be able to decrypt it except the person with her private key, so her, however, I am able to decrypt the file even if I delete the original unencrypted copy of the file.  How is this working?  I'm using the built-in seahorse encryption tools in Debian Linux.

Link to comment
https://www.neowin.net/forum/topic/1409550-asymmetric-encryption-question/
Share on other sites

39 minutes ago, BudMan said:

Normally when you encrypt something  to someones public key, you also encrypt it with your own public key - so you can decrypt it, since you have your private key.

I set up a clean VM and imported only one secret key and was able to decrypt a file that I encrypted with the other person's public key, so that makes sense.  It also explains why our PGP encrypted chat app lets me see all the messages I sent regardless of what device I sent it from.  Interesting how a file can basically be encrypted twice with two different keys and not affect the file size in any meaningful way though.image.png.511753f9fd455cc586b5499db68732b0.png

Well the file is not really encrypted multiple times.. What happens is the session key used to actually encrypt the data which would be symmetric, and and included in the message is encrypted with the recipients public key.. So they can decrypt the symmetric key and use that to decrypt the actual data you wanted to encrypt.

 

This is included in the header of the file..

 

But yeah it is really interesting/cool! ;)

On 11/07/2021 at 08:13, BudMan said:

Well the file is not really encrypted multiple times.. What happens is the session key used to actually encrypt the data which would be symmetric, and and included in the message is encrypted with the recipients public key.. So they can decrypt the symmetric key and use that to decrypt the actual data you wanted to encrypt.

 

This is included in the header of the file..

 

But yeah it is really interesting/cool! ;)

This prompted me to go do some reading and I didn't know that's how PGP worked.  I was under the impression that when you encrypted a file or something, it was actually encrypting the entire message with the public keys, so encrypting to multiple recipients would mean encrypting the file multiple times with different keys.  Doing things the way you described makes a lot more sense because symmetric encryption is faster, and this provides a method for sharing the symmetric key in a secure manner, kinda like how https/tls works when browsing the web.  I'm curious what actual encryption algorithm and strength is used then because you could have a really strong PGP key, but if the randomized symmetric key algorithm is weak, then an attacker wouldn't have to break RSA or Elgamal or whatever, they would just have to break the weaker symmetric algorithm that was used to encrypt the actual message.

5 hours ago, Good Bot, Bad Bot said:

Are you really using PGP to communicate with your wife? Why not just use Signal?

We do, it's our default fallback and where we have all our friends and family, but we also like experimenting with other options and found a very nice Android XMPP app called Conversations that supports either OMEMO or PGP encryption, so I decided to try out the PGP functionality. One of the down sides to Signal is that it's tied to a phone number, so my kids couldn't use it without me having to actually get them their own phone numbers. Having an independent registration method like Session Private Messenger or an XMPP server is kinda nice.

6 hours ago, Gerowen said:

We do, it's our default fallback and where we have all our friends and family, but we also like experimenting with other options and found a very nice Android XMPP app called Conversations that supports either OMEMO or PGP encryption, so I decided to try out the PGP functionality. One of the down sides to Signal is that it's tied to a phone number, so my kids couldn't use it without me having to actually get them their own phone numbers. Having an independent registration method like Session Private Messenger or an XMPP server is kinda nice.

it seems like a lot of work to keep "Buy some milk on the way home" secret unless you and the wife work for an alphabet agency or something.  I use SMS with my wife LOL but can't use iMessage and won't use WhatsApp. I do use Signal for certain communications with some contacts. Phone numbers are free and easy to get.

1 hour ago, Good Bot, Bad Bot said:

it seems like a lot of work to keep "Buy some milk on the way home" secret unless you and the wife work for an alphabet agency or something.  I use SMS with my wife LOL but can't use iMessage and won't use WhatsApp. I do use Signal for certain communications with some contacts. Phone numbers are free and easy to get.

I'm just a firm believer in encryption/security by default. Too many companies and agencies see it as their right to collect and monetize as much as possible, so we both deleted our Facebook accounts and told people if they want to get in touch with us to use Signal. There's nothing we talk about that's that interesting, but for us it's a matter of principal. If I call her while she's away on the weekend visiting her family and we decide to talk politics, I don't want somebody keeping recordings of our conversations and trying to either monetize it or use it against us at some point in the future. In a world where people like the NSA have stated their goal is to store all communications indefinitely and people are more politically divided than ever, it's more important than perhaps it has ever been to establish a secure enclave for your family to communicate without snooping and manipulation by third parties, no matter how innocent you might think your conversations are.

12 minutes ago, Gerowen said:

I'm just a firm believer in encryption/security by default. Too many companies and agencies see it as their right to collect and monetize as much as possible, so we both deleted our Facebook accounts and told people if they want to get in touch with us to use Signal. There's nothing we talk about that's that interesting, but for us it's a matter of principal. If I call her while she's away on the weekend visiting her family and we decide to talk politics, I don't want somebody keeping recordings of our conversations and trying to either monetize it or use it against us at some point in the future. In a world where people like the NSA have stated their goal is to store all communications indefinitely and people are more politically divided than ever, it's more important than perhaps it has ever been to establish a secure enclave for your family to communicate without snooping and manipulation by third parties, no matter how innocent you might think your conversations are.

I agree. Though I didn't get anybody on signal, but I did get my mom, dad, friend, sister and neice and nephew over to telegram from Facebook messenger.

 

It started when I drew my parents a picture of this and sent it to them on facebook messenger. 

 

image.png.223b24f7cb9277944cc2c4826a77e239.png

 

Then about an hour later I was seeing ads for this on Facebook

 

53152900_2336259906404558_4436535216282009600_n.thumb.jpg.486fa82772f9e0d67bf8b226de18a447.jpg

20 minutes ago, Gerowen said:

I'm just a firm believer in encryption/security by default. Too many companies and agencies see it as their right to collect and monetize as much as possible, so we both deleted our Facebook accounts and told people if they want to get in touch with us to use Signal. There's nothing we talk about that's that interesting, but for us it's a matter of principal. If I call her while she's away on the weekend visiting her family and we decide to talk politics, I don't want somebody keeping recordings of our conversations and trying to either monetize it or use it against us at some point in the future. In a world where people like the NSA have stated their goal is to store all communications indefinitely and people are more politically divided than ever, it's more important than perhaps it has ever been to establish a secure enclave for your family to communicate without snooping and manipulation by third parties, no matter how innocent you might think your conversations are.

I agree in a perfect world all communication would be E2EE and I could chat with anyone will any client but that is not possible. Principle is great and all but I need to communicate with others. Telling everyone it's Signal or nothing is not a real solution. Yes, no Facebook and more sensitive communication is via E2EE but I do compromise on regular everyday communication. The NSA can store those messages forever if they like. LOL What's next? We have cameras everyone so will we need to whisper to people we are talking to in public while covering our mouths as to not have our lip movements recorded?

30 minutes ago, Good Bot, Bad Bot said:

I agree in a perfect world all communication would be E2EE and I could chat with anyone will any client but that is not possible. Principle is great and all but I need to communicate with others. Telling everyone it's Signal or nothing is not a real solution. Yes, no Facebook and more sensitive communication is via E2EE but I do compromise on regular everyday communication. The NSA can store those messages forever if they like. LOL What's next? We have cameras everyone so will we need to whisper to people we are talking to in public while covering our mouths as to not have our lip movements recorded?

I made a Facebook post 30 days before deleting my account explaining my decision and gave people ways to contact me, then posted again about 2 weeks out. I figured anybody who values talking to me will respect my choices and if they don't, they obviously didn't value me enough to be slightly inconvenienced. I've even got the people at work to start using Signal to talk to me. It took about 6 months of them trying and failing to get me back on Facebook before they finally caved because they couldn't send large files or images over SMS. I don't personally think it should be so taboo to want privacy in your day to day personal communications. I do compromise and agree to use SMS occasionally for people that I don't talk to often, but if I talk to somebody on a regular basis and especially if they're a family member that wants pictures of my kids or something, I insist that they use Signal or some other E2EE means of communication and right now Signal is the easiest to get people on board with. I can't protect everything, but that doesn't mean I shouldn't make a reasonable effort to do what I can to protect myself and my family from unlawful spying that we know is taking place at the hands of corrupt, power hungry government officials, identity thieves, etc.

I haven't been big into pgp for years and years..  But my understanding the symmetrical key normally stronger.  Keep in mind the weakest link in the chain is what to worry about.. Be it the public asymmetrical or the session key (symmetrical).. But even if they break the session key used.  That would be different for every single message, so at best if they did break the session they would just have access to that message.  Since every time you encrypt something the session key would be different.

 

And your correct is somewhat like https/tls - where a secure method is used to exchange the key to be used for that session. 

  • 3 weeks later...
On 13/07/2021 at 09:29, warwagon said:

I agree. Though I didn't get anybody on signal, but I did get my mom, dad, friend, sister and neice and nephew over to telegram from Facebook messenger.

 

It started when I drew my parents a picture of this and sent it to them on facebook messenger. 

 

snipped

 

Then about an hour later I was seeing ads for this on Facebook

 

snipped

That's creepy as hell.  My wife and I deleted our Facebook accounts a few years ago.  It was a lot of things really; being sold as a product to advertising companies, intentionally spying on users, storing passwords in plain text, allowing third parties access to user information without their informed consent.  My wife actually deleted hers first.  I gave everybody a 30 day heads up, made a couple of posts explaining our decision, made a backup of my profile data and then deleted my account.  It's still kinda weird because I'll occasionally talk to somebody who wants to message me on Facebook or something and I have to explain to them that I don't have an account and refuse to make a new one even just for messenger when there are better options available.  I finally got all the guys at work on Signal because I just straight up refused to install Facebook Messenger.  My brother and I experimented with "Session" for a while because it's not tied to your phone number, so it's a bit more portable, but I haven't really made any real attempts to move people anywhere else except for our inter-family conversations my wife and I bounce between Signal and "Conversations.im" with our personal PGP keys.  We have actually noticed that even though it's based around the same protocols, the audio calls on conversations are more reliable than on Signal.  On Signal sometimes if she's out of the service area Signal will still report that a phone is ringing, when in fact it's not.  With conversations.im it "discovers devices" first and if it can't ping her phone, it tells me as much instead of letting me sit there listening to a ring tone as if her phone is ringing when it's not.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Posts

    • Liene PixCut S1 Starter Kit gets a whopping 31% discount on Prime Day by Steven Parker Liene reached out to us to share another Prime Day exclusive deal that starts today on Amazon. It gives buyers a massive 31% off on the cost of this color sticker printer and cutting machine. It's basically an all-in-one sticker maker for DIY crafts, custom labels and gifts. It utilizes thermal dye-sublimation at 300 dpi, and offers precise "AI" auto-cutting. Here are some more of its highlights: All-in-One Convenience - Print and Cut in One Step. Say goodbye to the hassle of using separate machines. The PixCut S1 seamlessly integrates high-resolution photo printing and precise die cutting into one streamlined device. With just a few clicks on the user-friendly app, you can edit, print, and cut directly from your smartphone via Bluetooth. Create stickers in just 2 minutes! This all-in-one solution saves you time and effort, making your creative projects more enjoyable and efficient. AI Image Extraction & Precision Cutting - Unleash your creativity with the AI image extraction feature that automatically recognizes and extracts subjects from your photos. Then watch as the high-precision cutting system, guided by the same AI technology, perfectly follows every edge with pinpoint accuracy. This seamless AI-to-cut workflow ensures flawless results every time. Turn any moment into custom stickers with professional edges in minutes - just masterpieces made simple. High-Resolution Prints - Vivid and True-to-Life Colors. Utilizing thermal dye-sublimation technology, the PixCut S1 delivers stunning 300 dpi high-resolution prints with 16.7 million colors. Whether you're printing photos, stickers, or labels, you can expect vibrant, true-to-life color effects that make your creations stand out. Every detail is captured with precision, providing professional-quality results every time. AI Lab - Bring Your Imagination to Life. Upload a photo, pick a style from the Liene Photo App, and watch AI bring your vision to life instantly. Turn selfies into an anime character, a fantasy hero, or a festive holiday illustration — all with stunning realism. One style, endless versions of you. Print your AI art as custom stickers, unique gifts, or social media posts — perfect for avatars and DIY projects. No design experience required. Your creativity is just one click away from magic. Durable Stickers - Create Long-Lasting Creations .Thanks to the four-layer thermal dye-sublimation technology, the photopaper is automatically laminated during printing. Stickers produced by PixCut S1 are durable, waterproof and scratch-resistant, ensuring they remain vibrant and intactover time. Perfect for creating custom stickers, labels, and more that last. No Subscription. Just Pure Creativity. With the Liene app, available on mobile, tablet, and desktop. Unlock 40,000+ free images, fonts & elements (and growing), plus 2000+ ready-to-use templates for phone skins, lens stickers, ID cards, labels, name tags, journaling, and more. No paywalls, no hidden fees, just pure creativity. Turn any idea into a custom creation in minutes. Your imagination has no limits, neither should your software. This deal is for the Starter Kit, so what do you get? What's in the box PixCut S1 Photo Sticker Printer and Cutter x 1 Photo Sticker Cutter Ink Cartridge x 1 (36 sheets) Photo Paper 4"x6" (18 sheets) Sticker Paper 4"x7" (White) x 18 sheets Blade x 1 (Pre-installed) So in short everything you need to get printing and cutting. The Liene PixCut S1 has a 4.3 star rating after more than 1,000 reviews from customers, but we can't promise the landing page always sold this particular model, so do check out the reviews before purchasing. In any case Prime members are covered with a 30 day return or replacement should things not work out so great. Liene Pixcut S1 for $205.99 (was $299.99) 31% off Use code 15PIXCUT6 during checkout Although this is a Prime Day discount, the above code will stay live until June 30. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • https://www.tenforums.com/tuto...b-results-windows-10-a.html Check the comment dates. Some of them are as old as 2016.
    • I wonder how many are laid off for cost savings, and this being blamed on AI to make it sound less scary and bad, for a more positive "modern, with the times" spin for investors? Because Oracle is down 14% the past year. We're looking at a company struggling here. If AI would actually be working out so well for them that they can do massive layoffs, surely this would've been reflected the past year in their stock value?
    • AI is the beginning, wait until real robots replace more jobs, specifically jobs that require physical work.
    • AI is indeed eliminating jobs, and Oracle just proved it by Hamid Ganji There’s no question that AI has become the hottest trend in workplaces, and every company is trying to adopt AI-driven solutions across its operations. While some industry leaders repeatedly say AI won’t lead to massive layoffs, recent data suggest that AI is actually one of the main reasons some companies are reducing their workforce. According to Oracle’s annual regulatory filing, the company has laid off about 21,000 employees, or 13% of its workforce, amid increasing AI adoption. “The adoption and deployment of AI technologies across our operations have resulted, and may continue to result, in reductions to our workforce,” Oracle said in the filing. The software giant now has approximately 141,000 full-time employees, a notable decrease from 162,000 during the same period last year. Restructuring expenses, including severance payments, cost Oracle $1.84 billion in fiscal 2026. Additionally, around 49,000 Oracle employees were based in the U.S., while approximately 92,000 were employed internationally. Like many other companies, Oracle has fully embraced AI and concentrated much of its efforts on the technology. The company is also a key participant in the United States’ $500 billion Stargate Project, which aims to build multiple AI data centers across the country. When it comes to AI adoption and its impact on the workforce, opinions remain divided. NVIDIA CEO Jensen Huang, whose company has been one of the biggest beneficiaries of the AI boom, recently said in an interview that attributing job cuts to AI is a “lazy” narrative. “The narrative that connects AI to job loss, for many of the CEOs that are doing it – it is just too lazy. AI has just arrived, how is it possible they're already losing jobs?” Huang said. However, statistics and recent reports tell a different story. According to Layoffs.fyi, 196 tech companies have laid off about 119,800 employees so far this year. Reducing staff and replacing roles with AI agents could become one of the most significant trends in the job market in the years ahead.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      464
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      97
    4. 4
      Michael Scrip
      89
    5. 5
      neufuse
      70
  • Tell a friend

    Love Neowin? Tell a friend!