@heiseonlineenglish More accurately, the GnuPG project has disagreed with some of the proposed fixes and are not doing them. I have not looked closely at them (The GunPG project is more knowledgeable than me). But I agreed with GnuPG in at least one case: https://news.ycombinator.com/item?id=46404589

This might be an example of the common case where the people who find the vulnerability should not be the ones to devise a fix or decide if a fix is required.

#PGP #openpgp #gnupg

One of those WONTFIX's is on an insane vulnerability: you can bitflip known plai... | Hacker News

@jan once details are published, and #39c3 is over, well take another look. But note that #deltachat's usage of #openpgp is intentionally minimal. #Gpgfail is a lot about failures of signature verification, and parsing problems in the gpg c-implementation but #deltachat doesn't use these mechanisms or code at all. The @rpgp folks are still studying the details, and there might be issues, so maybe also follow them for more details. Again, this doesn't affect deltachat as things stand.

Relax 😎! GPG is not OpenPGP!

Yesterday, vulnerabilities were published https://gpg.fail but they don't affect #deltachat or other #chatmail clients because

A) We never used #gnupg for anything; we use the modern #rustlang #openpgp implementation @rpgp, security audited multiple times.

B) #openpgp is fine, as modernized in #RFC9580, which already warns against several #gpgfail issues (gpg didn't implement that spec)

Please spread the word that #gpg is not #openpgp ... Thanks! #39c3

gpg.fail

I’m looking at age for many times especially to replace OpenPGP. They did a new release and for encryption at rest, it’s indeed a good replacement.

But how to integrate it with email encryption ? They recently did a keyserver https://words.filippo.io/keyserver-tlog/ and release an update version of age.

Are we close to a real replacement for OpenPGP ?

#pgp #age #openpgp

https://github.com/FiloSottile/age/releases/tag/v1.3.0

Building a Transparent Keyserver

We apply a transparency log to a centralized keyserver step-by-step, in less than 500 lines, with privacy protections, anti-poisoning, and witness cosigning.

@Foxboron the easiest way is to switch to an alternative #openpgp implementation, of which there are many. The closest in general functionality is probably sequoia, but most people don’t need a full-fat codebase and can use anything that supports the SOP interface

@hko Sorry to bug you, but have you picked a license yet for your #OpenPGP project in #Rust?

Obviously your choice, but I admit I'm on a mission to advocate for more Rust software under #copyleft licenses.

Cc: @liw @nlnet

In 2026, my main focus is the https://codeberg.org/minipgp6/ #OpenPGP stack.

#minipgp6 is a very small implementation of a minimal modern subset of OpenPGP, in #Rust.

The project aims to be both a comprehensive introduction to OpenPGP (for anyone who wants to approach the ecosystem from the shallow end) as well as practically useful software for contexts that don't require backward-compatibility with legacy formats.

(Many thanks to @nlnet for supporting this project!)

minipgp6

A very small implementation of a modern subset of OpenPGP 🔐🤏 Simple, secure, standards-based

Codeberg.org

I'm going to be in #Florence and #Rome for a couple days, followed by #Zermatt for a few more. I've never actually signed anybody's #pgp #gpg keys, but hey! Perhaps this could be a chance to learn how to do that *and* add some trans-atlantic edges to that web of trust!

#Italy #Switzerland #OpenPGP #WebOfTrust

Mi clave OpenPGP en el sitio

Hace tiempo que uso OpenPGP para correo electrónico, pero hasta ahora mi clave pública estaba… por ahí. Así que, además de cambiarla hace menos de un mes y publicarla en un servidor, decidí hacer algo simple y coherente: publicarla correctamente en el sitio, de forma visible, verificable y sin depender de terceros. ¿Qué publiqué? A partir de ahora, en el sitio podés encontrar: Una página dedicada con mi clave pública OpenPGP El fingerprint visible en el footer de todas las páginas La clave descargable en formato .asc Todo esto apunta a facilitar que cualquiera pueda enviarme un correo cifrado o verificar mi identidad cuando nos comunicamos por este medio.

Damián Muraña

The only way to stop this shitshow [legally!] is to #EncryptHarder and refuse to provide data & details!

And most importantly:

#USpol #EUpol #DEpol #politricks #politics #USA #Cyberfascism #Palantir #SurveillanceState #TechIlliterates #MediaIlliterates #illiteracy #technology #surveillance #AI #Enshittification #PoliceState #NSAbook #StasiBook