The code base and CLI could also be modernized so that developers could easily use its API. Sequoia is doing a good job here.
Otherwise, it risks becoming obsolete.
11–20 of 36 posts
The code base and CLI could also be modernized so that developers could easily use its API. Sequoia is doing a good job here.
Otherwise, it risks becoming obsolete.
Earlier quoted context omitted.
Vote with your wallet.
If the military wants something, and you want the same thing, is that a problem?
[1] They don't want the enemy (whoever that happens to be at the time) to be able to keep secrets as securely as they want to keep their own secrets.
[2] An accidental backdoor or side-channel vulnerability not fixed nor mitigations made known publicly, because it is useful once discovered and they have mitigations to protect their use, for instance.
They partnered with https://en.wikipedia.org/wiki/Rohde_%26_Schwarz - so basically GnuPG is now funded by military auxiliaries…
Earlier quoted context omitted.
If the military wants something, and you want the same thing, is that a problem?
The concern many have with military involvement in encryption and other security standards is that while they want for themselves exactly what we want for ourselves, they have an internal conflict of interests due to the fact that they want a bit of the exact opposite for other actors¹ which, if those concerns win out and they have the influence to force through or block changes, this could lead security issues² that…
I'm curious to hear why the BSI migrated back to Windows, but didn't find anything with a quick search. Any more information on this?
GnuPG needs to push to update OpenPGP to stay alive. OpenPGP needs to be updated. It lacks modern AEAD (the practical impact of a better authentication might be low in many use cases; but it has become a political problem). The code base and CLI could also be modernized so that developers could easily use its API. Sequoia is doing a good job here. Otherwise, it risks becoming obsolete.
In the ways that GnuPG is normally used the practical impact is zero because that is not how a stateless, offline protocol works. The content is authenticated by signing it directly, thus avoiding the extra complexity of a stateful connection oriented authentication scheme. The details here:
* https://articles.59.ca/doku.php?id=pgpfan:authenticated
So should functionality be added here for what would be purely political reasons? Or should the political purpose be spun off into a separate utility?
They partnered with https://en.wikipedia.org/wiki/Rohde_%26_Schwarz - so basically GnuPG is now funded by military auxiliaries…
duplicate to https://news.ycombinator.com/item?id=29775420
That post hardly generated any attention (2 comments). But there was a substantial discussion last week: https://news.ycombinator.com/item?id=29714752