Here's the source: https://github.com/wiktor-k/openpgp-proofs#openpgp-proofs
69 karma · joined October 12, 2018
Here's the source: https://github.com/wiktor-k/openpgp-proofs#openpgp-proofs
And mpv with "hwdec=vaapi" in ~/.config/mpv/mpv.conf
In private window it just works but still I consider the design of checking login on a page that doesn't require it quite bad.
Comparison of all these tools to GnuPG is valid and it clearly shows not only implementation problems but design ones as well in gpg.
What I fear is future riddled with all these incompatible tools. Even if they're written by brilliant engineers and cryptographers they are not standards (e.g. IETF standards). Why is that important? For example rewriting libsignal from scratch (for example to publish it under permissive licenses) can be problematic [0].
> DNS-Based Authentication of Named Entities (DANE) Bindings for OpenPGP
WKD has some benefits over OPENPGPKEY - it keeps the request confidential (as WKD uses plain HTTPS). WKD is just easier to get right, that's why it's more broadly supported. GnuPG, that supports both of them, defaults to WKD. If OPENPGPKEY request is made it seems GnuPG doesn't even validate DNSSEC signatures: https://lists.gnupg.org/pipermail/gnupg-users/2011-December/...
That's why most recent versions of GnuPG automatically create keys with expiry set to 2 years.
Interestingly I just read about this in a Lawrence M. Krauss book [0] where it was described that David Hilbert insisted on hiring Noether by the university but was overruled by the male majority that didn't like the idea that a female would teach male students. Hilbert commented that "this is university, not a bath-house!" [1].
[0]: I think it was "The Greatest Story Ever Told—So Far"
[1]: I'm writing that from memory so excuse some inaccuracies.
All major distros adopted it and even some that are listed there as "no systemd" in reality just give you choice (e.g. Gentoo).
I'd gladly hear the opinion of distro maintainers why did they switch to SystemD if it's as bad as it looks like in people's perception.
It's interesting to look back at the role Mr. Gultsch played in this XMPP revival. He correctly identified features missing or present in other messengers (e.g. offline files or good mobile connectivity), wrote appropriate specs (e.g. [0]) and made sure they went through XSF, implemented them in his client, helped implement it in other clients and implemented some of them in servers, or procured server developers to do so. Then he made sure that server administrators have an easy way to check compliance that ultimately led to SSLLabs-like online checker [1] that was a GSOC project that he also mentored.
Quicksy was conceived to test if the idea of phone number-based contact discovery would bring more people to XMPP. He's not just talking about stuff, he's actually implementing his ideas to check if they work!
This proactive approach is something that truly amazes me, especially when the default response of many people is cynicism and ranting that "the world is bad".
I don't want to downplay role of other people here but I'm 100% sure if it wasn't for Daniel's involvement we wouldn't be talking about XMPP today.
Recently a spin-off of Conversations - Quicksy was introduced [0] [1] that makes the entry even easier as it offers phone number-based contact discovery. From my experience people are used to quick on-boardings and don't even want to think about things like "username" and looking for contacts.
[0]: https://quicksy.im/
[1]: https://play.google.com/store/apps/details?id=im.quicksy.cli...