You want a specific tool for each of these use-cases. Choose one from the list for each use case.
1. Private messaging: Signal, WhatsApp, Cwtch
2. File encryption: age
3. Encrypted backups: age + a Reed-Solomon encoder for catching flipped bits
4. Digital signatures: minisign, signify, OpenSSH signatures
The problem with GPG (and with PGP in general) is it tried to do too many things. Complexity is the enemy of security.
I fear that I might of caused this idea. I have as a result added the following footnote to the article that I suspect is the cause[1]:
>Please note that the single flipped bit here is not a realistic example and that in practice damage tends to encompass one or more media blocks. Such blocks tend to be multiples of 512 bytes.
I am afraid that someone might actually implement this...
This list item was prompted by a private discussion with friends.
WhatsApp’s record over the last decade does not inspire confidence, and the issues raised this year alone are quite serious:
https://wikipedia.org/wiki/Reception_and_criticism_of_WhatsA...
It's just a foundation-sort of program that does encryption and signing of arbitrary data, using one format for keys, and allowing working with those keys whether they're in the same computer or in a smartcard/hsm. That simplifies key management, since it allows you to have one Yubikey with your PGP key on it and do basically anything crypto related.
But what I believe someguydave was referring to was stuff like smartcard/Yubikey support, not different uses of encryption and signing.
https://twitter.com/FiloSottile/status/1474941666545086465 ¯\_(ツ)_/¯
Bug jedisct1 if you want YubiKey support for minisign.
I've reviewed both the design and implementation for age in the past and only found nitpicky things to improve (mostly related to HKDF).
I can take a fresh look and make a pretty PDF on paragonie.com if you care so much.
Hell, I have shirts older than the language it's written in.
In 20 years, I might not even be able to find a working compiler to build it, after the shiny-object crowd moves on to something else.
You know what I'll still be able to decrypt? An ASCII-armored, GPG encrypted, TAR archive.
Personally, I am not interested in the latest evolutionary improvements on file formats. Evolution produces a lot of interesting things; most of them are dead ends. What I want is the cockroach of file formats. The coelacanth.
No. Brand new means completely new. Something that's going on 3 years old isn't brand new anymore.
A more appropriately term is relatively new. Civilization is relatively new compared to the age of the universe. Age is relatively new compared to modern computers.
But neither civilization nor age are brand new.
Using common libraries, I can create a python program to decrypt a file produced by age in a few hours, I think.
Frankly in my reading of your question you come across as very arrogant, where you use the guise of a “serious question” to show off your knowledge cryptography.
There have been many articles written that push back against the narrative a small cohort of security people push that GnuPG and OpenPGP by extension should be avoided at all costs. Personally, I find it has stood the test of time admirably and that its "multi-tool" functionality unlocks features I use almost every day like a web of trust in Keybase and using it as an ssh agent. I actually don't want another tiny tool in age. With Sequoia the future of PGP looks bright.
This thread has been both interesting and educational.