Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Wiktor Kwapisiewicz

@wiktor@metacode.biz
  • Open on metacode.biz

I work on cryptographic software and integration with hardware security modules (TPMs, PKCS#11...) primarily in 🦀 Rust:

◆ tss-esapi
◆ cryptoki
◆ ssh-agent-lib
◆ @wiktor-k@crates.io

I have been involved in several OpenPGP projects and co-authored the book 📚 “OpenPGP for application developers”.

A significant portion of my projects have been financed via the 🇪🇺 Next Generation Internet program thanks to substantial help from the NLnet Foundation.

I ❤️ open-source and try to contribute wherever I can. Check out my links! When no-one is watching I'm developing ActivityPub software...

152 Followers
0 Following
3 Posts
Joined January 28, 2016
ArchLinux Staff:
https://archlinux.org/people/support-staff/#wiktor
GitHub:
https://github.com/wiktor-k
SteamOS GitLab:
https://gitlab.steamos.cloud/wiktor
Me elsewhere:
https://keyoxide.org/aspe:metacode.biz:CK7LM6VO32K2AGIDXC7LYFRBSA
📍:
🌌 ☀️ 🌍 🇪🇺 🇵🇱
Open post
Wiktor Kwapisiewicz @wiktor@metacode.biz
· 6mo ago
Replying to
Haha! :) By the way, it seems the current PQC draft spec has an escape hatch: there’s one algo that can be used with v4 keys for encryption: https://datatracker.ietf.org/doc/html/draft-ietf-openpgp-pqc-17#section-4.3.2 Of course support for that would have to be done in several clients to be interoperable but it seems other clients are also looking for replacing their existing OpenPGP libraries with something modern: https://github.com/wiktor-k/pysequoia/issues/54#issuecomment-3965522660
Post-Quantum Cryptography in OpenPGP
IETF Datatracker

Post-Quantum Cryptography in OpenPGP

This document defines a post-quantum public key algorithm extension for the OpenPGP protocol, extending RFC9580. Given the generally assumed threat of a cryptographically relevant quantum computer, this extension provides a basis for long-term secure OpenPGP signatures and ciphertexts. Specifically, it defines composite public key encryption based on ML-KEM (formerly CRYSTALS-Kyber), composite public key signatures based on ML-DSA (formerly CRYSTALS-Dilithium), both in combination with elliptic

1
3
0
0
Open post
Wiktor Kwapisiewicz @wiktor@metacode.biz
· 6mo ago
Replying to
The underlying library (PGPainless) doesn’t support PQC (https://datatracker.ietf.org/doc/html/draft-ietf-openpgp-pqc-17) yet (?) but technically it’s possible. I skimmed the relevant specs (https://xmpp.org/extensions/xep-0373.html) and sadly it seems they reference the old OpenPGP spec (RFC 4880, a.k.a. "v4") instead of the newer one (RFC 9580, a.k.a. "v6") which is expected to be extended with PQC any minute now.
Post-Quantum Cryptography in OpenPGP
IETF Datatracker

Post-Quantum Cryptography in OpenPGP

This document defines a post-quantum public key algorithm extension for the OpenPGP protocol, extending RFC9580. Given the generally assumed threat of a cryptographically relevant quantum computer, this extension provides a basis for long-term secure OpenPGP signatures and ciphertexts. Specifically, it defines composite public key encryption based on ML-KEM (formerly CRYSTALS-Kyber), composite public key signatures based on ML-DSA (formerly CRYSTALS-Dilithium), both in combination with elliptic

0
5
0
0
Open post
Wiktor Kwapisiewicz @wiktor@metacode.biz
· 5mo ago
Replying to

Haha, that’s my cue, right? 😅

I’ll recap what I said elsewhere, the benefits of SSH over OpenPGP, as currently used:

  • no need for specialized destructuring with custom-made tools (https://gitlab.archlinux.org/archlinux/archlinux-keyring/-/tree/master/keyring/packager?ref_type=heads) just a simple, human-readable file: https://github.com/openssh/openssh-portable/blob/master/.git_allowed_signers If someone changes a key or expiration you don’t need to parse base64 in your head :)

  • SSH signatures have a namespace field, thus making signature reuse harder but “there is no context separation for signatures in OpenPGP” (https://bugzilla.mozilla.org/show_bug.cgi?id=1953402#c3)

  • small technical details on how the signature is generated that makes it easier to integrate with HSMs (we’ve got quite an elaborate format for that in Signstar)

  • full-fledged verifier is truly a “weekend project”! https://github.com/wiktor-k/ssh-sig

OpenPGP has a couple of advantages but this thing is already a bit too long to read ;)

gitlab.archlinux.org

keyring/packager · master · Arch Linux / Arch Linux Keyring · GitLab

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:59:14 UTC