Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Heiko

@hko@floss.social
  • Open on floss.social

Various #OpenPGP-related activities, mostly in #Rustlang.

- Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6@floss.social)

- Contributor to @rpgp@mastodon.social

- Blog/writeups: https://openpgp.foo

- OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

0 Followers
0 Following
50 Posts
Joined April 28, 2025
codeberg:
https://codeberg.org/heiko
OpenPGP for application developers:
https://openpgp.dev
v4 OpenPGP certificate:
https://pgpkeys.eu/pks/lookup?op=get&search=0x23da7c0eaa711f0170013595b518d342eb2d4805

Posts

Open post
hko
Heiko @hko@floss.social · Jul 19, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
As a total aside, this test-Gnuk is running on an ST-LINK v2 clone that I bought ~5 years ago when I first hacked on https://crates.io/crates/openpgp-card See https://nx3d.org/gnuk-st-link-v2/ for more.
3
1
1
0
Open post
hko
Heiko @hko@floss.social · Jul 19, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
The key material from RFC 9580 Appendix A.4 on my test Gnuk (https://www.fsij.org/doc-gnuk/intro.html) $ oct status OpenPGP card FFFE:57092840 Signature key: Fingerprint: 060606060606060600000000cb186c4f0609a697 Creation Time: 2022-11-30 16:08:03 UTC Algorithm: EdDSA (Ed25519) Signatures made: 3 Decryption key: Fingerprint: 06060606060606060000000012c83f1e706f6308 Creation Time: 2022-11-30 16:08:03 UTC Algorithm: ECDH (Curve25519) [..]
0
1
0
0
Open post
hko
Heiko @hko@floss.social · Jul 19, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Over the last half week, I've implemented very barebones #OpenPGP card support in @minipgp6@floss.social Support is limited to Ed25519 and X25519 (since that's the intersection of what minipgp supports and what current cards support). As expected, there is no fundamental obstacle that prevents use of existing OpenPGP card devices with v6 keys. #rfc9580
8
1
5
0
Open post
hko
Heiko @hko@floss.social · Jul 02, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @tante@tldr.nettime.org
@tante@tldr.nettime.org according to https://en.wikipedia.org/wiki/Electric_energy_consumption#World_electricity_consumption the global total electricity consumption is ~25.000 TWh. That would make the aggregate current usage of the big tech corporations (as shown in Ketan's second image) very roughly 1% of all of humanity's electricity use. Exponential growth continuing from currently ~1% sounds even more horrifying than what I had imagined so far. Here's hoping that this unhinged waste of energy stops sooner rather than later.
0
0
0
0
Open post
hko
Heiko @hko@floss.social · Jun 08, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @ell1e@hachyderm.io
@ell1e@hachyderm.io my comment contains multitudes. Including sarcasm. And doom.
0
0
0
0
Open post
hko
Heiko @hko@floss.social · Jun 08, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @ell1e@hachyderm.io
@ell1e@hachyderm.io I was thinking the same thing as I wrote it - but then, they have decades of experience at being a wide range of shades of evil. They probably don't need my advice.
1
1
0
0
Open post
hko
Heiko @hko@floss.social · Jun 07, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @ell1e@hachyderm.io
@ell1e@hachyderm.io "Digital Crimes" 🤦 Maybe they could also mix accusations of (cyber) "terrorism" into this matter 🤪
1
1
0
0
Open post
hko
Heiko @hko@floss.social · May 05, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @upofadown@mstdn.ca
@upofadown Schemes based on RFC 9580 are going to be quite interoperable. I'm aware of at least 7 serious independent codebases that implement RFC 9580, and almost as many mature implementations of draft-ietf-openpgp-pqc. Adding autocrypt2 to the mix is a very small additional layer on top of these already widely available building blocks. (And sure, GnuPG is doing its own thing. But that is really not very relevant to Delta Chat or its users.)
2
0
0
0
Open post
hko
Heiko @hko@floss.social · May 02, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
My current goal for #minipgp6 is to clarify the target shape for an eventual v0.1.0 release. The v0.0.x series serves strictly as a prototype. This is why v0.0.1 lives in the separate "draft" git branch. Once prototyping is complete, I will start implementing the v0.1 series from scratch, in the git "main" branch.
1
0
1
0
Open post
hko
Heiko @hko@floss.social · May 01, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hipsterelectron@circumstances.run
@hipsterelectron once the dust around the base minipgp6 stack settles, I plan to write a convenience crate for AC2 key generation and rotation. Would love to hear your thoughts when you read the draft!
1
0
0
0
Open post
hko
Heiko @hko@floss.social · May 01, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
@hipsterelectron I have not engaged with that draft yet, but minipgp6 is conspicuously matching the algorithm requirements of the scheme 😏
1
0
0
0
Open post
hko
Heiko @hko@floss.social · May 01, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hipsterelectron@circumstances.run
@hipsterelectron have you seen https://datatracker.ietf.org/doc/draft-autocrypt-openpgp-v2-cert/ ?
1
2
1
0
Open post
hko
Heiko @hko@floss.social · May 01, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hipsterelectron@circumstances.run
@hipsterelectron thank you! this needs so much work still, but it's such a relief to have put this initial version out in the world! ... a very smol pgp! 🥺🔏
1
1
0
0
Open post
hko
Heiko @hko@floss.social · May 01, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

I just released a first draft version of #minipgp6

@minipgp6@floss.social

minipgp6 is an intentionally small #OpenPGP library stack.
It implements v6 formats from https://www.rfc-editor.org/rfc/rfc9580 and #PQC composite key algorithms from https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/

The complete library stack in this release adds up to ~5k LOC.
It interoperates with all modern OpenPGP libraries: https://codeberg.org/minipgp6/minipgp6#interop

A SOP CLI tool based on minipgp6 can be installed as

$ cargo install minipgp6-sop

Many thanks to @nlnet@social.nlnet.nl

18
3
15
0
Open post
hko
Heiko @hko@floss.social · Apr 28, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @thermia@sk.girlthi.ng
@thermia 🙀
1
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 27, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

RE: @foss_north@fosstodon.org

Yay for @dvzrv@chaos.social 's tireless(*) work towards modernizing how OpenPGP is used in distro contexts (including in Arch Linux).

I've spent some time last year hacking on https://devblog.archlinux.page/2026/verify-arch-linux-artifacts-using-voa-openpgp/ with David, which was a great time.

VOA is the other side of the coin to Signstar - the former verifies signatures, while the latter produces them.

---

(*) Although I do suspect he might at times actually get tired, after all 🤔

6
0
7
0
Open post
hko
Heiko @hko@floss.social · Apr 27, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @annaecook@mastodon.social
@annaecook@mastodon.social
1
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 27, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
A new and PQC-relevant email thread: https://lists.gnupg.org/pipermail/gnupg-users/2026-April/068280.html I consider the author of that mail (@andrewg@mastodon.ie) one of the most evenhanded and patient people in PGP. He has a lot of context, both on the technical side, and regarding the social dimension. His mail hits many nails on their heads. It's unfortunate that the PQC situation in OpenPGP (or well, in GnuPG) has derailed as it has. But here we are. I'm glad Andrew is spelling out uncomfortable points. And still hopes for common ground.
3
0
1
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @andrewg@mastodon.ie
@andrewg@mastodon.ie @giacomo yolo!
0
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
@duxsco@fedifreu.de This is of course complicated by GnuPG effectively attempting to derail these developments But I don't think there is anything constructive left to do, in that regard. Many people have tried to build many bridges. To no avail. The only remaining option is to try and protect captive GnuPG user bases from the fallout, as much as possible. This is the goal of @freepg@infosec.exchange The GnuPG situation is not great. But I think the ecosystem is being as constructive as circumstances allow. Which is nice
0
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @duxsco@fedifreu.de
@duxsco@fedifreu.de The good thing is that no one is forced to deal with GnuPG's increasingly odd choices. My perspective is that there is really only one sensible path forward: The formats that are developed by the OpenPGP WG at the IETF. There are half a dozen independent implementations of both RFC 9580 and draft-ietf-openpgp-pqc. It's clear that there is a lot of consensus, and will to modernize in a collaborative fashion.
1
1
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @duxsco@fedifreu.de
@duxsco@fedifreu.de @giacomo 👍 It is confusing that two related but separate issues are overlapping here: 1) There is a Free Software codebase (GnuPG), the code of which is not "proprietary software" in the FSF sense. 2) However, this Free Software project is increasingly an implementation of a format ("LibrePGP") that is developed in a proprietary manner, in an entirely intransparent process.
0
1
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @CyReVolt@mastodon.social
@CyReVolt @daslabor I see what you're saying, in the list of contributors, yes. I was vaguely aware of this project, but you just connected the dots in my mind a lot more solidly.
1
1
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @CyReVolt@mastodon.social
@CyReVolt oh wow! I had no idea you were involved in that. It's wild to think how many attempts to leave the gravity well of GnuPG there already were. Hopefully we'll reach escape velocity, finally.
1
1
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @CyReVolt@mastodon.social
@CyReVolt the naming of the https://freepg.org/ patchset might have included a smirk and a wink in that general direction
1
1
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @neverpanic@chaos.social
@neverpanic@chaos.social @darkuncle@infosec.exchange frankly, after observing this mess for quite a while, I think these explanatory models are not fully convincing. Sure, there are animosities, and they do play a role. But I don't believe they are the ultimate root cause. About the technical "arguments" (such as the complaints about GCM in RFC 9580), I have come to believe that those are entirely disingenuous parallel constructions.
2
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @darkuncle@infosec.exchange
@darkuncle@infosec.exchange I find it truly hard to understand what exactly is going on with GnuPG, but I consider the analysis in https://mastodon.ie/@andrewg/116464399797066586 one of the more compelling theories about why this is all unfolding as it is.
1
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @andrewg@mastodon.ie
@andrewg@mastodon.ie @aspensmonster@tenforward.social @petelawler@mastodon.social I very much agree with Andrew's analysis. (Fwiw, I think there is no conceivable monetary incentive for GnuPG to fork away from the OpenPGP standard.)
0
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 25, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @giacomo@snac.tesio.it
@giacomo I mean that GnuPG's new, non-OpenPGP formats are "proprietary in the governance sense": One actor unilaterally decides what they want to do, while not meaningfully engaging with anyone else. Then they implement their preference, and write up some document that more or less describes the format. Think https://en.wikipedia.org/wiki/Office_Open_XML
1
2
0
0
Open post
hko
Heiko @hko@floss.social · Apr 24, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @pid_eins@mastodon.social
@pid_eins @dvzrv welcome to 90s retro nerddom!
3
1
0
0
Open post
hko
Heiko @hko@floss.social · Apr 24, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
GnuPG exists for one sole reason: The original PGP crew in the 1990s decided that open standards, collaboration and multiple implementations are cool. So they published their - at the time groundbreaking - formats, and standardized them at the IETF. GnuPG has benefited massively from this, while at the same time being a software that no one I know has ever truly enjoyed. I certainly have not. This project is now attempting to do a standardization rug pull. It's ridiculous and enraging.
18
2
8
0
Open post
hko
Heiko @hko@floss.social · Apr 24, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
Also see https://chaos.social/@dvzrv/116460347482223544 It would appear that GnuPG upstream is trying to use its influence to create facts on the ground (by proliferation of its proprietary non-OpenPGP formats).
3
2
2
0
Open post
hko
Heiko @hko@floss.social · Apr 24, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @letoams@defcon.social
@letoams @dvzrv @freepg It's certainly not in a good place. But it does seem determined to drag the rest of OpenPGP down, with its weird antics.
1
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 24, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

Regular PSA reminder:

While GnuPG 2.5.x implements hybrid PQC encryption based on ML-KEM, just like https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/, GnuPG's implementation is entirely incompatible with the IETF-specified format, which all other libraries are implementing.
Both serialization and the KEM combiners differ.

The bottom line is that anyone who wants to use vendor-agnostic PQC with OpenPGP should *avoid GnuPG's PQC key formats*.

This is all exceedingly unfortunate and weird, and frankly, a total disgrace.

23
4
33
1
Open post
hko
Heiko @hko@floss.social · Apr 21, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

I just released version 0.1.9 of rsop-oct, a stateless #OpenPGP ("SOP") CLI tool for use with OpenPGP card hardware devices:

https://crates.io/crates/rsop-oct/

Like its sibling project #rsop, rsop-oct is based on @rpgp@mastodon.social

This version improves error handling and reporting in some cases, in particular when a suitable card is not found, or the User PIN for a card is not available.

For more on #SOP, see https://datatracker.ietf.org/doc/draft-dkg-openpgp-stateless-cli/

#PGP #GnuPG

2
0
2
0
Open post
hko
Heiko @hko@floss.social · Apr 10, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @daniel@gultsch.social
@daniel @nlnet amazing, congrats! Yay for more modernized OpenPGP subsystems. And it's great to see PGPainless getting used in more places 🥳
1
0
0
0
Open post
hko
Heiko @hko@floss.social · Apr 09, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @pancake@infosec.exchange
@pancake @delta @gnome 🤔🥳
2
0
0
0
Open post
hko
Heiko @hko@floss.social · Mar 31, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

I just released version 0.1.7 of rsop-oct, a stateless #OpenPGP ("SOP") CLI tool for use with OpenPGP card hardware devices:

https://crates.io/crates/rsop-oct/

Like its sibling project #rsop, rsop-oct is based on @rpgp@mastodon.social

This update adds (initial) support for the SOP command 'update-key'.

This command allows extending the expiration times of components of an OpenPGP certificate using a primary key that is stored on an OpenPGP card device.

For more on #SOP, see https://datatracker.ietf.org/doc/draft-dkg-openpgp-stateless-cli/

#PGP #GnuPG

6
0
5
0
Open post
hko
Heiko @hko@floss.social · Mar 30, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hzulla@infosec.exchange
@hzulla The more you know! 🤓
0
0
0
0
Open post
hko
Heiko @hko@floss.social · Mar 28, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @tarakiyee@mastodon.online
@tarakiyee I love how the text doesn't aim to tear down an imperfect argument, but add to and improve it! A discursive world with more principledness, but less tearing down would be nice 😃
1
0
0
0
Open post
hko
Heiko @hko@floss.social · Mar 19, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

The openpgp-card-state crate now has a new "ephemeral" backend:

https://codeberg.org/openpgp-card/state/#ephemeral-interactive-input-with-persistence-and-expiry

This combines the defensiveness of unpersisted pinentry with the convenience of caching (in the Linux kernel credential store, for a configurable duration).

New releases of https://crates.io/crates/openpgp-card-tool-git, https://crates.io/crates/openpgp-card-ssh-agent, https://crates.io/crates/rsop-oct support this new #OpenPGP card PIN storage backend.

Many thanks to @classabbyamp@chaos.social who implemented this new PIN handling mechanism in openpgp-card-state.

4
2
4
0
Open post
hko
Heiko @hko@floss.social · Mar 18, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @liw@toot.liw.fi
@liw I do think there are some reasons to worry - but not about skilled programmers losing their privileged position in the job market. My impression is that a lot of the frenzied discourse is caused by two facts: 1) a few corporations are spending ridiculous amounts of money, and some of it on propagandizing, and 2) these LLM techniques do have some kernel of utility for some software engineering-related tasks. I enjoyed the perspectives in this recent conversation: https://dair-community.social/@timnitGebru/116237328338979566
3
0
0
0
Open post
hko
Heiko @hko@floss.social · Mar 17, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @evan@cosocial.ca
@evan@cosocial.ca I'm glad these valiant truth-seekers have gotten the guy who spray paints hopeful symbolism on walls sorted. I assume they will now shift their keen investigative minds to reporting about Palantir's sales process. Or whatever. This is going to be great!
1
0
0
0
Open post
hko
Heiko @hko@floss.social · Mar 14, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
I set up a containerized build environment to facilitate working on the GnuPG IETF PQC branch: https://codeberg.org/freepg/freepg-draft-ietf-openpgp-pqc/src/branch/main/build The goal of adding #IETF #PQC support to @freepg is still very many steps away. But it's nice to have a foundation to start from :)
3
0
1
0
Open post
hko
Heiko @hko@floss.social · Mar 08, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

The https://freepg.org/ project maintains patches against #GnuPG with the goal of closer adherence to the IETF #OpenPGP spec.

One currently open question is if/how draft-ietf-openpgp-pqc support could be realistically added to #FreePG

I've started https://codeberg.org/freepg/freepg-draft-ietf-openpgp-pqc first of all as a notes-to-self repo for a (presumably very slow and long-term) side quest to explore this problem.

Specifically, the goal would be adding support for v4 ML-KEM-768+X25519 subkeys.

https://www.ietf.org/archive/id/draft-ietf-openpgp-pqc-17.html#ecc-mlkem

freepg.org

FreePG Project

FreePG patches GnuPG to maintain OpenPGP compatibility, fix bugs, and help downstream distributors

10
1
11
0
Open post
hko
Heiko @hko@floss.social · Feb 17, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
That minipgp6-based SOP binary interoperates nicely with all other RFC 9580 implementations I've tested, including with PQC algorithms. And the entire binary literally fits on a 💾 🥳 As I anticipated, RFC 9580 *really shines* ✨ in implementations that leave out all of the legacy parts. The #OpenPGP WG at the #IETF specified an excellent modernization, with the "v6" formats. RFC 9580 perfectly balances full backward compatibility with *massive* forward-looking simplifications.
2
0
2
0
Open post
hko
Heiko @hko@floss.social · Feb 17, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
Update on #minipgp6 My draft implementation is almost feature complete, albeit still rough around some edges. It supports traditional Ed25519/X25519 plus the two MTI PQC hybrids from draft-ietf-openpgp-pqc. ("OpenPGP component validity" semantics is still missing.) The (very modular) stack of libraries currently weighs a total of ~4.2k LOC. The SOP CLI tool implementation is 1.5k LOC. A build of the SOP binary is 1.3 mbyte (with size-optimization settings for the compiler/linker) #OpenPGP
3
1
1
0
Open post
hko
Heiko @hko@floss.social · Feb 17, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @mechko@chaos.social
@mechko@chaos.social In the past, I've tried to "keep up" with microblogging feeds. Now I just treat them as broadcasts that I sometimes "tune into", read the last tens of messages, and maybe follow some rabbitholes in them. But I don't try to read the full timeline. Orthogonally, I'm experimenting with enabling notifications for some (low volume) accounts that I follow, to reliably see *all* of their posts (in my notification timeline).
1
1
0
0
Open post
hko
Heiko @hko@floss.social · Feb 05, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social
Replying to @hko@floss.social
The initial plan for minipgp6 was to support only the "mandatory to implement" algorithms from RFC 9580. In terms of public key algorithms, this would mean: only Ed25519 and X25519. However, in the meantime, draft-ietf-openpgp-pqc has made much progress - IETF-standardized PQC support in #OpenPGP is going to get rolled out in various places soon. So I'm amending the plan: minipgp will optionally support the two "mandatory" composite #PQC algorithms "ML-KEM-768+X25519" and "ML-DSA-65+Ed25519".
9
2
2
0
Open post
hko
Heiko @hko@floss.social · Feb 04, 2026
Heiko
@hko@floss.social

Various #OpenPGP-related activities, mostly in #Rustlang. - Very lean modern OpenPGP: https://minipgp6.org/ (@minipgp6) - Contributor to @rpgp - Blog/writeups: https://openpgp.foo - OpenPGP card (hardware security device) projects: https://codeberg.org/heiko#openpgp-card

floss.social

minipgp6 is happening.

https://codeberg.org/minipgp6/ 🔐🤏

For the past four weeks I've immersed myself in writing an extremely minimal, modern #OpenPGP software stack.

There's still a lot of work ahead, but the current draft code already feels quite exciting.
It's very modular and currently weighs just over 5k LOC (including a small Stateless OpenPGP CLI tool).

I look forward to publishing a first version of the code in the coming weeks 🚀

#rfc9580 #RustLang #PGP

0
3
19
0

Remote instance

floss.social
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:48:15 UTC