The tinfoil hat part of me has been seeing this push for the Signal protocol straight out of nowhere and am a little worried its being done by a state level actor who knows something about it that we don't. Its much younger than PGP and as such has had less eyes on it. I also don't think Moxie Marlinspike, the founder of Signal's owner - Open Whisper, has the cred and trust Phil Zimmerman had, at least not yet. Its particularly worrisome as he seemingly is only known by a pseudonym.
I also would consier S/MIME, which is baked into most feature-heavy email clients including iOS, a practical alternative to PGP when the use case is email encryption. You and a friend can get certs easily, put them in your client via GUI, and be done with it. No command line skills needed if ease of use is the big complaint here. For the less technically inclined its a pretty good solution, pun intended.
on a different note: gnupg is not widely used, signal is.
Signal is not fit for PGP's use case.
Not quite true.
> every message has the recipient keyid in plaintext
The keys are not required to be centralized in any particular location. There is no way to tie a key to an individual, unless that individual wants to be associated with that key id.
It's common practice to post anonymous, encrypted messages on mailing lists or newsgroups. All you can really tell in those cases is that the recipient is a member of that mailing list or subscribes to the newsgroup (though it's not for sure, with the use of remailers, etc).
How large?
> several recipients
How many, in what countries?
Is the communication anonymous?
Can I use it in such a way that obfuscates the message's recipient?
Can I send an encrypted message when the Signal servers have been DOSed?
If seized, can the controllers of the Signal servers get the contents of my entire phone contact list?
I believe that Signal is adequate for a small subset of encrypted message cases, but not as a good replacement for encrypted emails.
I'm unaware that Signal is geographically limited in any way.
Signal is anonymous as your phone number is. PGP isn't anonymous either, so this seems like an irrelevant criticism.
Again, you can obfuscate the recipient as much as you can obfuscate a phone number. You can't obfuscate the email address you're sending your encrypted email to.
This depends on how they use contacts to match users. I believe they only collect a hash of the phone numbers you choose to share with them.
It's true that PGP is a very good code signing system, but saying that sounds like an endorsement of PGP as a privacy system. (And there are plenty of other good code signing systems, from TUF to Authenticode to signify.)
This vaguely sounds similar to how RSA decryption/encryption and signing/verification are the same sets of operations, at the primitive level, making it easy to turn a tool that does one in to a tool that also does the other. But the actual high-level signing and encryption systems (e.g. RSA-PSS and RSA-OAEP) are not the same operations at all, and being good at one is no guarantee of being good at another.
Same basic concept. Take a blob (compiled code or cyphertext) and a private key and sign it, so can be verified with the public key later.
https://en.wikipedia.org/wiki/Authenticated_encryption
This kind of PGP signing is also critical to the security of Linux software repos. Debian repos sign the contents of the manifest (which includes hashes of packages), and Apt repos sign individual files.
I use PGP as part of my backup solution, encrypting my backups at rest with an asymmetric key. I can't do that with Signal.
Except for endpoint security. The ultra-portable, self-contained implementations of PGP can run on countless configurations of desktop or embedded system. Transport methods also vary if they're funning messages or files through other apps. All sorts of hardening or isolation techniques can be applied. Remote attackers have a lot to look at trying to break or bypass GPG for an arbitrary user. Whereas, vast majority of Signal use relies on one app with two OS's.
The extra security tech and obfuscation you can layer on PGP/GPG is still an advantage in its favor until competition gets that.
I won't disagree; when your usecase is in Signal's wheelhouse, by all means, use it.
But as someone who uses PGP regularly; the limit of how I could use Signal instead of PGP is limited to the occasional transfer of PII, passphrases, and private keys (something I couldn't use Signal for, since these are typically sent between GUI-less hosts). A very tiny fraction of my PGP usage.
Signal the protocol or Signal the service? There does not appear to be a mature FOSS toolchain for the former that can replace gnupg and Thunderbird/Enigmail, and the latter is only available on Android and IOS smartphones.
Using PGP/GnuPG isn't always easy, but it works for so many things. Signing code, encrypting files, emails, signing messages - replacing it is a fairly high bar.
I'd love to see encryption easy and used everywhere, but a few popular apps don't add up to replacing this old work horse.