Post #914922
2025-07-08 13:53 UTC
A new report (commissioned by the German BSI) outlines the recent evolution of the #OpenPGP standard, including the new RFC 9580 and PQC drafts, as well as the spinoff "LibrePGP" draft that the GnuPG project writes.
PDF: https://github.com/crypto-security-tools/OpenPGP-LibrePGP-comparison/releases/download/v1.4/opgp-lpgp-comp.pdf
(Announcement email: https://mailarchive.ietf.org/arch/msg/openpgp/2g_rjYBqwqKZE6OEgjNb0bFo098/)
Note that the document contains a one-page "Executive Summary", which (although quite technical) is worth a read.
[TL;DR: It raises concerns about the GnuPG draft's development process, as well as quality]
Replies (1)
-
@Anarcat@kolektiva.social 2025-07-08 14:54
@hko also, holy moly, LibrePGP still allows DSA? #wtf? there's also a couple of vulnerabilities in the librepgp protocol disclosed in there...