#openpgp

11 posts · Last used 9d

Zero days since it turned out that #GnuPG has arbitrarily changed behavior between versions in the name of "safe default", and required you to pass an additional option to make it behave properly in the rare cases it matters. Of course we still need to support old versions and alternative implementations without that option. And of course there is no clean way of checking whether it's available or not. https://bugs.gentoo.org/983021 #OpenPGP #GPG #Gentoo
8
3
4
0
Apparently the so-called "schism" in #OpenPGP is over. Context: In 2022, an email to the IETF OpenPGP working group list, titled "a new draft overlapping the WG draft", noted that one implementation (GnuPG) seemed to reject the draft that is now RFC 9580: https://mailarchive.ietf.org/arch/msg/openpgp/PWp3ZcZ_qnDNLhuT-zR7gA2ddeg/ Today, the author of #GnuPG signaled on the IETF list that he intends to implement support for RFC 9580 and draft-ietf-openpgp-nist-bp-comp: https://mailarchive.ietf.org/arch/msg/openpgp/B7ytSFXTVW84UfFd4cCW-DXhpAA/ As I see it, this is great news for OpenPGP!
32
6
16
0
Mein PGP-Keygenerator auf dem Weg zu Post-Quantum Ich möchte euch nur kurz informieren, dass Post-Quantum-Kryptografie in PGP nicht mehr allzu weit entfernt ist. Mit RFC 9980 wurde inzwischen der offizielle IETF-Standard für Post-Quantum-Kryptografie in OpenPGP veröffentlicht. ➡️ Verschlüsselung: hybride Verfahren mit ML-KEM + ECC ➡️ Signaturen: hybride Verfahren mit ML-DSA + EdDSA Jetzt fehlt im Wesentlichen noch die entsprechende Umsetzung in OpenPGP.js. Sobald diese Unterstützung dort sauber integriert ist, werde ich auch meinen PGP-Keygenerator um standardkonforme Post-Quantum-OpenPGP-Schlüssel erweitern. :boost_ok:#OpenPGP #PGP #Verschlüsselung #Keygenerator #Datenschutz #Security #Secunis #ITSecurity
4
2
4
0
Replying to
@9yyiw179ykv56evd@fed.interfree.ca Maybe checkout #ox (#OpenPGP for #XMPP). It's not as complicated as #OMEMO. it's currently supported by #profanity, #gajim and #GoSendxmpp. #Conversations is currently working on support.
0
2
0
0
Gerade den Nitrokey 3A Mini gekauft. Er ersetzt künftig meinen alten Nitrokey Storage und dient mir für OpenPGP bei E-Mails, die SSH-Anmeldung per Public Key sowie die Smartcard-Anmeldung unter Linux. Den verschlüsselten Massenspeicher brauche ich nicht mehr - dafür ist der neue Nitrokey deutlich kleiner und kann dauerhaft am Notebook bleiben. #Nitrokey #OpenPGP #SSH #Linux
50
10
15
2
Over the last half week, I've implemented very barebones #OpenPGP card support in @minipgp6@floss.social Support is limited to Ed25519 and X25519 (since that's the intersection of what minipgp supports and what current cards support). As expected, there is no fundamental obstacle that prevents use of existing OpenPGP card devices with v6 keys. #rfc9580
9
1
5
0

A public project should not be credible only because it appears online.

This is why I am using ProofBundle for the projects I publish and discuss publicly, including the ones I present here on LinkedIn.

ProofBundle creates a portable cryptographic proof for a project snapshot.

It takes the files, builds a deterministic SHA-256 manifest, reduces the entries into a Merkle tree, and produces one Merkle root for the whole project state.

Then that root is bound to a signed author/custody claim.

ProofBundle can also use OpenTimestamps: the Merkle root and manifest hash are timestamped and anchored to public blockchains, without uploading the original project and without putting the contents on-chain.

So the proof has three layers:

  • integrity: SHA-256 hashes, manifest, and Merkle root
  • identity/custody: Ed25519 or OpenPGP signature
  • time evidence: OpenTimestamps blockchain anchoring

For signing, ProofBundle supports a default Ed25519 mode: modern, compact, and easy to verify.

It can also use a detached OpenPGP signature, including OpenPGP keys based on Ed25519. And for stronger key custody, OpenPGP signing can optionally be backed by a YubiKey, so the private signing key stays hardware-backed and non-exportable.

This is not copyright registration and it is not a legal shortcut.

It is technical evidence that:

  • this exact project state existed
  • these files matched this manifest
  • this Merkle root represented the snapshot
  • this key signed the claim
  • the timestamp evidence was

anchored through OpenTimestamps

  • the proof can be verified independently

Full technical note: https://www.gabrielesalati.eu/blog/proofbundle-verifiable-project-integrity.html

#ProofBundle #OpenTimestamps #Blockchain #OpenPGP #Ed25519 #MerkleTree #YubiKey #CyberSecurity #SoftwareEngineering #OpenSource

0
0
0
0
Congrats to @protonprivacy@mastodon.social for beating us on introducing Post-Quantum Cryptography into mail messaging! No worries. We'll implement https://autocrypt2.org which additionally offers reliable deletion / forward secrecy during 2026 :) We are working with Proton cryptographers on OpenPGP specifications, and they are now moving towards using @rpgp@mastodon.social , the end-to-end encryption we are using. Everything will be based on RFC9580 (#OpenPGP v6) ... the eocsystem is moving :) https://proton.me/blog/introducing-post-quantum-encryption
169
17
120
2
You've seen all posts