someone asked me to name the developer i talked to. i won't do that because in the past devs have been verbally attacked and threatened. justified or not, this is not acceptable behavior, and i am not going to expose anyone to that.
on the question of LibrePGP being the work of one person, i already mentioned that i found that the old OpenPGP RFC 4880 is 90% unchanged in LibrePGP. turns out it goes even further. almost all of the LibePGP RFC was already created by the OpenPGP committee. until some people pushed for massive changes. it was only at that point that werner koch decided to fork the standard and publish the old, already agreed upon, almost ready for publication, version of OpenPGP as LibrePGP with minimal changes. so this whole idea that LibrePGP is the work of one person is simply not true. this is documented in the timeline on https://librepgp.org/#timeline
the key issue with the new OpenPGP standard is not the changes in the supported crypto standards, but the incompatible key format, including the removal of the old keyformat. think about this for a moment please. clearly crypto algorithms need to be revised and improved over time, but there should be very little need to revise the key format, and especially remove support for the old format. i haven't verified this, but with the support for an old format gone, any old documents written in that format can no longer be decrypted by software following the new standard. the unreasonableness of this change is likely what set werner off, because he could not possibly remove support for the old format from GnuPG without breaking things for almost every user.
LibrePGP therefore is not an incompatible fork of OpenPGP, but OpenPGP RFC5980 is an incompatible revision of OpenPGP RFC4880 and of the latest consensus before people decided to massively change the OpenPGP RFC.
on the claim that GnuPG keeps silently releasing 2.2 versions, there is a simple explanation for that: GnuPG 2.2 is certified by the German Federal Office for Information Security (BSI). until a new version of GnuPG gets that certification, certain institutions that require this certification are not able to upgrade. think of 2.2 as an LTS release only intended for those that need it. there is nothing malicious about it, and insinuating that stopping support for 2.4 is in bad faith when 2.2 is still supported is simply missing the point. projects that have LTS releases do that all the time.
that mentioned refusal to backport something to 2.4 was not a refusal but an oversight. it has since been fixed.
the issue with the supposedly removed systemd support was a surprise to the person i talked to. but he could not confirm either way. we'll research that and follow up (feel free to email me if there is no reply here before the time to reply expires in two weeks. my email is in the profile). what my contact did tell me is that the systemd integration somehow made it more difficult to use GnuPG without that integration on machines running systemd. i didn't quite understand why though. if i learn more about this, i'll post it.
claims that the problem is the age of gnupg's codebase, which supposedly bakes in a lot of assumptions and premature optimisations, and which also supposedly doesn't have any unit tests or continuous integration, that it's a codebase that few outsiders understand and which few insiders are confident about making major changes to are very interesting but pretty baseless.
i mean how do you even make a claim that the codebase is full of assumptions and premature optimisations? what is the evidence for this claim? same for lack of tests. a claim like that would be very easy to verify. so please show your evidence, and don't make up stuff.
in my opinion this whole controversy is caused by people not listening to each other, and it is embellished by people who only follow one side of the argument and take everything that side claims as the truth. i am not exactly neutral myself, as i consider the GnuPG devs my friends, but i have a strong interest in resolving conflicts and misunderstandings and harmonizing different viewpoints. so i hope that my comments here are not adding fuel to the fire, but rather help to douse out the fire or at least cool it down.
it is also my hope that at some point in the future the differences between the new OpenPGP RFC and LibrePGP can be resolved, and the standards can be merged. (i don't know, it might be as simple as reinstating support for the old key format). forking a project in the face of controversy is not unknown in the FOSS community. it famously happened with GCC for example and a few other well known projects, which managed to overcome their differences and merge again. but to make this happen we need to stop throwing around accusations and actually listen to people to learn the reasons for their choices and opinions.
as long as we fight, we will just hinder each other in making progress. only if we collaborate and resolve our differences are we able to learn from our mistakes and move forward. this, btw, is the mantra that i live for, and this is why i chose to get involved in this discussion.
please share this comment with anyone who needs to see it.