At work, we use it to store shared secrets. We can encrypt a file that can be decrypted by multiple keys.
It's a bit hard to remember all the commands so I made a webUI to manage everything.
The feature I like the most is that I can list which files you can access and which files you cannot.
The thing is, to do that, I need to pass tons of obscure and magic nonsense parameters IE:
gpg --list-only --no-default-keyring --secret-keyring /dev/null ops.gpg
and then parse the completely un-parsable output to know which keys can decrypt the file.So far so good. The problem is that; this magic trick only work with gpg 2.0.30 or lower. If you have the latest version, you can see every keys that can decrypt a file... except yours. There is no way to know if "You" can decrypt a file anymore ! (how great is this)
I now have to tell people that if they want to use the nice UI they cannot have the latest version of gpg, which is troubling.
I can't believe that in 27 years, it is still impossible to know which keys can decrypt a file. Or even just have some parsable output instead of the pile of crap the gpg tool can vomit out.
So I'm pretty excited about Sequoia :)