Heiko
mastodon 4.7.3Various #OpenPGP-related activities, mostly in #Rustlang.
- Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6@floss.social)
- Contributor to @rpgp@mastodon.social
- Blog/writeups: https://openpgp.foo
- OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card
@jonah@mastodon.neat.computer this is definitely a hard time to feel hopeful about tech.
My silver linings perspective is that we're collectively getting a lot of new clarity about what we disagree with, and what world we'd prefer to inhabit instead.
Some of the "evils" are new, but many have been here a long time, and we've just gotten better at seeing them with a critical eye.
Maybe this depressing moment is a necessary intermediate step towards making a better tech world for ourselves - and everyone.
Yay for @dvzrv@chaos.social 's tireless(*) work towards modernizing how OpenPGP is used in distro contexts (including in Arch Linux).
I've spent some time last year hacking on https://devblog.archlinux.page/2026/verify-arch-linux-artifacts-using-voa-openpgp/ with David, which was a great time.
VOA is the other side of the coin to Signstar - the former verifies signatures, while the latter produces them.
---
(*) Although I do suspect he might at times actually get tired, after all 🤔
I just released version 0.1.7 of rsop-oct, a stateless #OpenPGP ("SOP") CLI tool for use with OpenPGP card hardware devices:
https://crates.io/crates/rsop-oct/
Like its sibling project #rsop, rsop-oct is based on @rpgp@mastodon.social
This update adds (initial) support for the SOP command 'update-key'.
This command allows extending the expiration times of components of an OpenPGP certificate using a primary key that is stored on an OpenPGP card device.
For more on #SOP, see https://datatracker.ietf.org/doc/draft-dkg-openpgp-stateless-cli/
The openpgp-card-state crate now has a new "ephemeral" backend:
https://codeberg.org/openpgp-card/state/#ephemeral-interactive-input-with-persistence-and-expiry
This combines the defensiveness of unpersisted pinentry with the convenience of caching (in the Linux kernel credential store, for a configurable duration).
New releases of https://crates.io/crates/openpgp-card-tool-git, https://crates.io/crates/openpgp-card-ssh-agent, https://crates.io/crates/rsop-oct support this new #OpenPGP card PIN storage backend.
Many thanks to @classabbyamp@chaos.social who implemented this new PIN handling mechanism in openpgp-card-state.
I just released version 0.1.9 of rsop-oct, a stateless #OpenPGP ("SOP") CLI tool for use with OpenPGP card hardware devices:
https://crates.io/crates/rsop-oct/
Like its sibling project #rsop, rsop-oct is based on @rpgp@mastodon.social
This version improves error handling and reporting in some cases, in particular when a suitable card is not found, or the User PIN for a card is not available.
For more on #SOP, see https://datatracker.ietf.org/doc/draft-dkg-openpgp-stateless-cli/