Signal is not fit for PGP's use case.
Signal is not fit for PGP's use case.
Not quite true.
> every message has the recipient keyid in plaintext
The keys are not required to be centralized in any particular location. There is no way to tie a key to an individual, unless that individual wants to be associated with that key id.
It's common practice to post anonymous, encrypted messages on mailing lists or newsgroups. All you can really tell in those cases is that the recipient is a member of that mailing list or subscribes to the newsgroup (though it's not for sure, with the use of remailers, etc).
How large?
> several recipients
How many, in what countries?
Is the communication anonymous?
Can I use it in such a way that obfuscates the message's recipient?
Can I send an encrypted message when the Signal servers have been DOSed?
If seized, can the controllers of the Signal servers get the contents of my entire phone contact list?
I believe that Signal is adequate for a small subset of encrypted message cases, but not as a good replacement for encrypted emails.
I'm unaware that Signal is geographically limited in any way.
Signal is anonymous as your phone number is. PGP isn't anonymous either, so this seems like an irrelevant criticism.
Again, you can obfuscate the recipient as much as you can obfuscate a phone number. You can't obfuscate the email address you're sending your encrypted email to.
This depends on how they use contacts to match users. I believe they only collect a hash of the phone numbers you choose to share with them.
It's true that PGP is a very good code signing system, but saying that sounds like an endorsement of PGP as a privacy system. (And there are plenty of other good code signing systems, from TUF to Authenticode to signify.)
This vaguely sounds similar to how RSA decryption/encryption and signing/verification are the same sets of operations, at the primitive level, making it easy to turn a tool that does one in to a tool that also does the other. But the actual high-level signing and encryption systems (e.g. RSA-PSS and RSA-OAEP) are not the same operations at all, and being good at one is no guarantee of being good at another.
Same basic concept. Take a blob (compiled code or cyphertext) and a private key and sign it, so can be verified with the public key later.
https://en.wikipedia.org/wiki/Authenticated_encryption
This kind of PGP signing is also critical to the security of Linux software repos. Debian repos sign the contents of the manifest (which includes hashes of packages), and Apt repos sign individual files.