#GnuPG 2.5.7 (dev) has been released (#OpenPGP / #GPG / #GNUPrivacyGuard / #PGP / #PrettyGoodPrivacy / #Security / #Gpg4win) https://gnupg.org/
#GnuPG 2.5.7 (dev) has been released (#OpenPGP / #GPG / #GNUPrivacyGuard / #PGP / #PrettyGoodPrivacy / #Security / #Gpg4win) https://gnupg.org/
#GnuPG 2.4.8 has been released (#OpenPGP / #GPG / #GNUPrivacyGuard / #PGP / #PrettyGoodPrivacy / #Security / #Gpg4win) https://gnupg.org/
Comparing #XMPP against #email protocols is too limited. What sets #deltachat apart is *vertical integration* and being driven by UI/UX considerations. Cross-platform Apps and Bots use the Rust core library which connects with #chatmail relays and classic email servers based on a higher level API -- abstracting over SMTP, MIME, #OpenPGP etc. See https://chatmail.at
#webxdc apps in turn use an even higher level stable API abstracting over email/xmpp/... see https://webxdc.org/docs/
Post-quantum cryptography
「 Defense against potential future attacks with quantum computers is of particular interest for encryption. In particular when it is relevant if an attacker might store encrypted communication and decrypt it in the future. Defending against such an attack requires deployment of countermeasures well before the attack becomes practical 」
The PGP Problem
https://www.latacora.com/blog/2019/07/16/the-pgp-problem/
#OpenPGP #GnuPG #PGP #GPG #PublicKey #Email
#AgeEncryption https://age-encryption.org
#Minisign https://jedisct1.github.io/minisign/
#AgePublicKey
age1s3n5ehvm8h3xjkc985hzjznw9cv0lk9ezj5heyy4m7l654rkzslq07ylps
#MinisignPublicKey
RWRK8XFYuCHjYX1J/7cKCUy6eQKNYVAurb/70Q6pK8kjGHALVORZGJ+o
Retired my 6 years old OpenPGP/GnuPG key today and replaced it.
Also updated the link to the public key in my Mastodon profile (stored on disroot.org).
gpg --edit-card
und dann einem verify
hinbekommen. Danach war der Schlüssel der aktuellen Karte zugeordnet.I just released version 0.1.2 of rsop-oct, a stateless #OpenPGP ("SOP") CLI tool for use with OpenPGP card hardware devices:
https://crates.io/crates/rsop-oct/
Like its sibling project #rsop, rsop-oct is based on @rpgp
This update makes integration with https://crates.io/crates/openpgp-card-state optional.
rsop-oct can now implicitly use persisted PINs via openpgp-card-state, or explicitly provided ones via the standard SOP CLI parameter '--with-key-password'.
For more on #SOP, see https://datatracker.ietf.org/doc/draft-dkg-openpgp-stateless-cli/
I just released version 0.7.0 of #rsop, a stateless #OpenPGP ("SOP") CLI tool based on @rpgp:
https://crates.io/crates/rsop/
This version uses the new rPGP 0.16.0, with streaming message support.
It also comes with a number of bugfixes.
For more on #SOP, see https://datatracker.ietf.org/doc/draft-dkg-openpgp-stateless-cli/
New release: #rPGP version 0.16.0
https://github.com/rpgp/rpgp/releases/tag/v0.16.0
#OpenPGP implemented in pure #Rust, permissively licensed
This release features streaming message support: Now rPGP can process arbitrarily large messages, with modest memory requirements.
It adds experimental support for the upcoming OpenPGP #PQC IETF standard https://datatracker.ietf.org/doc/html/draft-ietf-openpgp-pqc
This release also brings various improvements for key generation, support for X448/Ed448, and many minor fixes.
our friends over at @rpgp just published a monster milestone, humbly tagged 0.16 with
- streaming decryption and encryption
- post-quantum-cryptography
- API streamlining.
#rPGP is a full Rust implementation of #openpgp which counts among the fastest and most compliant implementations today, and includes security audits. Note: #deltachat uses a restricted subset of OpenPGP, and follows best practices (eg using the same ed25519 keys implementation as #signal) https://github.com/rpgp/rpgp/
#Gpg4win 4.4.1 has been released (#GnuPG / #OpenPGP / #GPG / #GNUPrivacyGuard / #PGP / #PrettyGoodPrivacy / #Security / #Kleopatra / #GPA / #GNUPrivacyAssistant / #GpgOL / #GpgEX) https://gpg4win.org/
But, more importantly: Getting a warning when my key is about to expire.
Luckily, this was pretty easy to write.
https://codeberg.org/scy/dotfiles/commit/9ef269f86356d80e53f6e7bbde9d85b65a21525f
[ theregister.com: Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms ]
https://www.theregister.com/2025/05/20/openpgp_js_flaw/
Well fuck. #PGP #OpenPGP #security #vulnerabilities
Don't use PGP with emails.
> Security researchers are sounding the alarm over a fresh flaw in the JavaScript implementation of OpenPGP (OpenPGP.js) that allows both signed and encrypted messages to be spoofed.
> Discovered by Codean Labs' Edoardo Geraci and Thomas Rinsma, the vulnerability essentially undermines the core purpose of using public key cryptography to secure communications.
**OpenPGP.js bug enables encrypted message spoofing**
A critical flaw in #OpenPGP.js lets attackers spoof message signatures
https://securityaffairs.com/178131/uncategorized/a-openpgp-js-flaw-lets-attackers-spoof-message-signatures.html
#securityaffairs #hacking
Critical OpenPGP.js Vulnerability Allows Spoofing https://www.securityweek.com/critical-openpgp-js-vulnerability-allows-spoofing/ #Vulnerabilities #EmailSecurity #emailsecurity #vulnerability #encryption #OpenPGP
Critical OpenPGP.js Vulnerability Allows Spoofing https://www.securityweek.com/critical-openpgp-js-vulnerability-allows-spoofing/ #Vulnerabilities #EmailSecurity #emailsecurity #vulnerability #encryption #OpenPGP