This may well be a good thing
This may well be a good thing
Posted Dec 7, 2023 12:28 UTC (Thu) by dsommers (subscriber, #55274)In reply to: This may well be a good thing by elenril
Parent article: A schism in the OpenPGP world
That's my feeling as well. And this extends further to just the OpenPGP standard itself. GnuPG has served its purpose of making PGP widely available on lots of platforms. But it is just horrendous to use in practice. I spent too much of my last weekend to migrate new PGP subkeys to a new set of Yubikeys. The steps needed to do subkey management is just too low-level for mere mortals. And then when GnuPG ends up leaving "old status cruft" in ~/.gnupg/private-keys-v1.d which needs to be manually resolved through debugging ....
I'm grateful for what Werner Koch has managed in regards to PGP availability, but GnuPG is far from a tool inviting new users to the PGP world. The efforts Proton has done is by far more user friendly (they've even made it basically transparent for users not specifically digging up the PGP keys).
What I do hope is that the Sequoia-PGP project can end up with a more reasonable and friendly user interface. I've not been able to compile it on my RHEL-8 setup yet for some proper testing, but the documentation certainly makes it look far more inviting. https://docs.sequoia-pgp.org/sq/
If Sequoia can truly establish itself as a proper alternative PGP implementation, I believe the days of GnuPG will see the end eventually. If Werner Koch really cares for OpenPGP and wants GnuPG to survive, he certainly should be far more careful in putting up blockers like this and kicking off forks like LibrePGP. Proton is also a too large PGP consumer to be ignored (with more than 100 million users); and they will push forward for more future safe crypto implementations.
Posted Dec 7, 2023 12:42 UTC (Thu)
by rahulsundaram (subscriber, #21946)
[Link]
RPM is using it these days so it should become available in more places
https://fedoraproject.org/wiki/Changes/RpmSequoia
Posted Dec 7, 2023 15:25 UTC (Thu)
by ballombe (subscriber, #9523)
[Link] (5 responses)
Posted Dec 7, 2023 15:29 UTC (Thu)
by dsommers (subscriber, #55274)
[Link] (4 responses)
Posted Dec 7, 2023 16:22 UTC (Thu)
by dd9jn (✭ supporter ✭, #4459)
[Link]
BTW, One good thing with the delays is that meanwhile Rogaway's patent on OCB expired and there is zero reason not to use OCB. FWIW, there has even always been a royalty free license for almost all software implementing OCB.
Posted Dec 7, 2023 17:53 UTC (Thu)
by ballombe (subscriber, #9523)
[Link]
Posted Dec 7, 2023 18:09 UTC (Thu)
by riking (subscriber, #95706)
[Link] (1 responses)
Posted Dec 7, 2023 19:02 UTC (Thu)
by dsommers (subscriber, #55274)
[Link]
https://en.m.wikipedia.org/wiki/Secure_Remote_Password_pr...
This may well be a good thing
This may well be a good thing
This may well be a good thing
This may well be a good thing
This may well be a good thing
Now proton is sitting on million of keys which are only protected by password that can be subject to various bruteforce attack. The security is much lower than what PGP provides.
This may well be a good thing
This may well be a good thing