Elektrine lite

← Feed

@hko@floss.social

Post #2408960

2026-04-24 12:13 UTC

Regular PSA reminder: While GnuPG 2.5.x implements hybrid PQC encryption based on ML-KEM, just like https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/, GnuPG's implementation is entirely incompatible with the IETF-specified format, which all other libraries are implementing. Both serialization and the KEM combiners differ. The bottom line is that anyone who wants to use vendor-agnostic PQC with OpenPGP should *avoid GnuPG's PQC key formats*. This is all exceedingly unfortunate and weird, and frankly, a total disgrace.

Replies (2)

  • @hko@floss.social 2026-04-24 19:07

    Also see https://chaos.social/@dvzrv/116460347482223544 It would appear that GnuPG upstream is trying to use its influence to create facts on the ground (by proliferation of its proprietary non-OpenPGP formats).

    Open ##2814548

  • @hko@floss.social 2026-04-27 15:48

    A new and PQC-relevant email thread: https://lists.gnupg.org/pipermail/gnupg-users/2026-April/068280.html I consider the author of that mail (@andrewg@mastodon.ie) one of the most evenhanded and patient people in PGP. He has a lot of context, both on the technical side, and regarding the social dimension. His mail hits many nails on their heads. It's unfortunate that the PQC situation in OpenPGP (or well, in GnuPG) has derailed as it has. But here we are. I'm glad Andrew is spelling out uncomfortable points. And still hopes for common ground.

    Open ##2814550