https://blog.cryptographyengineering.com/2014/08/13/whats-ma...
https://blog.cryptographyengineering.com/2014/08/13/whats-ma...
To put this in perspective, it's a little like someone invented a bad balanced binary tree before anybody else came up with a hash table or a radix tree or a heap, and then a weird subculture formed around that balanced binary tree based on the idea that you should only ever use that tree algorithm, even though someone subsequently came up with red-black trees that were superior in every way to the original.
It's a little like that culturally but it's almost entirely unlike that technically - a suboptimal data structure or algo tend to be just suboptimal-but-functional whereas bad cryptography and bad cryptography engineering often fail catastrophically. I know you know this, of course! But for one thing, someone used an iffy analogy on the internet, etc. For another, PGP people love misusing exactly this sort of analogy.
I deeply respect Philip Zimmermann for creating "pretty good privacy" rather than trying for "perfect privacy". PGP is exactly that: pretty good. Not great, not perfect, but pretty good indeed. And it's there. And it works. It's a compromise, which works well for many people's requirements. Oh, and did I mention that it EXISTS?
I use PGP every day. My private keys are stored on Yubikeys, which is supported. I have offline backups of those, which is supported, too. I can encrypt my backups for multiple keys, sign lists of hashes of files to verify integrity, and people can send me private E-mail.
None of this works perfectly, but it does work, and (not being a teenager anymore) I appreciate the fact that PGP has worked since 1991 or so, and I can reasonably expect it to work for the rest of my lifetime, unlike much modern software, which while being incredibly fashionable, seems to flare out a couple of years later.
The user should hold the keys, not a government or company.
Technical aspects are generally secondary, and should improve, but we shouldn’t dismiss good approaches due to implementation details.
I think U2F/WebAuthn dongles actually could solve this problem but there are all sorts of new problems now like "how do I use this with my iPhone and also with my PC" or "what happens when lose my (physical) keychain with my dongle".
A simpler way to make the same point would be that relative to modern cryptography, to a first approximation, nobody uses PGP.
"Don't worry, these few thousand techies are the only ones that need secure communication" is sheer arrogance.
While Debian and other package signing continues to use PGP (and yes, Debian may move away, and signify/minisign is preferable) there are lots of “infrastructure” uses.
It’s like a frog, which is about to beat a frog with a wand, frog says, come on, I am already a frog!
Having obscure arguments about the underlying cryptography is fun and all, but doesn't really make the world a better place.