A New Future for GnuPG
gnupg.org
gnupg.org
[2] https://www.cryptologie.net/article/502/alternatives-to-pgp/
In my day we used GPG and we liked it. Need to use a smartcard with a GPG key to SSH? well tie an onion to your belt and get ready to pull a standing triple gainer in bash. did you get the password prompt? well now its time to dive further young Padawan. Ease the cover of your X11 book open and pour through the warm inviting text of no fewer than three pinentry programs. balance the PGP and GPG manuals on each knee (thats what the onions for ya goof!) and study the .gpg config, as ed25519 may, or may not even be a PGP standard... perhaps the pin is entered properly in another TTY, so plug in your TTY monitor and get to work! easy as pie. still doesnt work? perhaps you still need to do a subkey cross-signature for your detatched authentication keys? it is now 4 AM which is when most "people" sleep but the prime witching hour for GPG divinations, stay true and persist!
now some people might say "validation and trust" are issues but back in my day we had key signing parties. oh they were all the rage, haughty and formal door-knob licking festivals (pre covid mind you) where you could greet your colleagues balancing a stale cookie on a plate and confirm --in the flesh-- this key was honest, and true and matched perfectly the arabica halitosis of the keyholder as they spittle their way through tales of last years divorce. Did your colleague from brussels get a haircut? hes dead to you now. revoke the key, burn every chair in your home, and seek out his new truth. to the GPG key servers!
and kids now a days will bemoan "keysevers!" rubbish. why, theres no more telltale glory than to sit at the helm of a CGI web form from 1991 as its calcified backend tucked deep in the bowels of some learn-a-torium lurches along the SUNOS disk platters querying an ocean, NAY, a veritable drowning pool of old keys of yore from anyone and anything. the mirthful chuckle from your first 512 bit key 17 years ago will sustain you! as you begin encrypting your message in no fewer than the seven keys listed for the faculty member to wihch you wish to divulge your nanas fudge recipe.
I'm curious to hear why the BSI migrated back to Windows, but didn't find anything with a quick search. Any more information on this?
It's not really surprising that a 100b company who specializes in writing software for specific business office-ish use-cases can beat an ad-hoc group of corporate volunteers mostly focused on the developer experience and the server space.
The code base and CLI could also be modernized so that developers could easily use its API. Sequoia is doing a good job here.
Otherwise, it risks becoming obsolete.
In the ways that GnuPG is normally used the practical impact is zero because that is not how a stateless, offline protocol works. The content is authenticated by signing it directly, thus avoiding the extra complexity of a stateful connection oriented authentication scheme. The details here:
* https://articles.59.ca/doku.php?id=pgpfan:authenticated
So should functionality be added here for what would be purely political reasons? Or should the political purpose be spun off into a separate utility?
For AEAD and OpenPGP, there seem to be limitations in the message format:
* https://datatracker.ietf.org/doc/html/draft-ford-openpgp-for...
Newer versions of GPG do support AEAD modes of operation, but AFAICT they only appear in the "encrypted data" part of the resulting bucket of data and not in the "signature" part. The algorithms are generally supported though; search for 'aead':
* https://www.gnupg.org/documentation/manuals/gnupg/OpenPGP-Op...
* https://www.gnupg.org/documentation/manuals/gcrypt/Available...
If you do not like PGP/GPG, you 'just' have to create a better way of doing things, and then 'just' have to convince everyone to switch their workflows to it.
[1] They don't want the enemy (whoever that happens to be at the time) to be able to keep secrets as securely as they want to keep their own secrets.
[2] An accidental backdoor or side-channel vulnerability not fixed nor mitigations made known publicly, because it is useful once discovered and they have mitigations to protect their use, for instance.
And as other recent issues highlight, open to many eyeballs does not necessarily imply completely robust and secure code.
They are one of the big 3 in this field along with Anritsu and Keysight.
Hmm :-)