For signing: signify/minisign
For encryption: age
For file transfer: magic wormhole
For encrypted messaging: Signal (or your choice of e2e encrypted messaging platform)
For signing: signify/minisign
For encryption: age
For file transfer: magic wormhole
For encrypted messaging: Signal (or your choice of e2e encrypted messaging platform)
How do you trust some key material. The WoT is a complete failure, but modern solutions like WKD are amazing and make PGP just plain work.
The one nice thing about age is the ability to encrypt to a GitHub users key. However, even that is possible with OpenPGP. Here is a tool that I made ~7 years ago that does something similar: https://github.com/georgyo/sshcrypt
Another thing minisign/age don't have is a method to say that a key is compromised.
I don't think the solution to the problems with OpenPGP is too just ignore the problems and switch to using bare keys like new tools are doing.
Here is an example of a cool tool with modern cryptography, forward secret etc, often recommended in HN as an alternative to Wormhole:
https://redrocket.club/posts/croc/
It turned out that plaintext could easily be recovered! One mistake and 100% broken.
There are benefits to an industry standard protocol.
They recommended Brian Warner's magic-wormhole, Signal, Tarsnap, age, Signify, Minisign, libsodium.
* https://articles.59.ca/doku.php?id=pgpfan:agevspgp
Age might be such a replacement some day for just the encryption function. But it has a ways to go. Actually defining the format would be a good first step.
The only valid criticism is about its handling of corrupted data, but for that too you can use an external tool like PAR2 to generate recovery data. I do this with my GPG backups and other data as well.
I like that age follows the Unix "do one thing well" philosophy, and that I can use other similarly scoped tools for other features. There are still some things I'm missing, but these are slowly being worked on[1,2].
I was responding to a comment that said that age was a "standard replacement" for GPG.
How would signal be compromised that email could not and which signal is not better prepared for?
I don't follow. Not everyone uses Gmail or the big email providers.
Right now that sits at about a 1 in 5 chance for Gmail alone.