Post #1574532
2025-07-08 14:54 UTC
@hko also, holy moly, LibrePGP still allows DSA? #wtf? there's also a couple of vulnerabilities in the librepgp protocol disclosed in there...
Replies (1)
-
@hko@floss.social 2025-07-08 15:06
@Anarcat FWIW, my own read is: The "LibrePGP" draft is a renamed copy of RFC 4880-bis (which hasn't seen much serious work since 2007), lightly edited to add a few new features that GnuPG wanted to implement. There was no rigorous re-work of the contents of RFC 4880, compared to the new IETF RFC 9580. And its new formats (like the "OCB" encryption container) don't seem to stand up very well to even mild scrutiny. (Which might be somewhat expected for a one-person drafting effort.)