3 ms·
OpenPGP is kind of like git - if you understand the underlying concepts (in case of OpenPGP this is RFC 4880) then it is simple. GPG is very old and created in
by Shoothe 9y ago
OpenPGP is kind of like git - if you understand the underlying concepts (in case of OpenPGP this is RFC 4880) then it is simple. GPG is very old and created in different times so it has many quirks at the implementation and UI level but I find the encoding and structures quite simple (there are some weird choices of course).
I wonder what do you think is complex? Trust model maybe? Different kinds of signatures? Negotiating algorithms to use?
- heavenlyblue 9y agoI think while I probably understand the underlying concepts better (cryptography-wise), there isn't much _practical_ infromation about GPG in the wild. Just as much as knowing how git works under the hood doesn't necessarily make you great at managing branches in git. More often than not it's way easier to just go with a sort of ready-made recipe, so that your workflow would be easily accepted by the industry; rather than read the doc.
- Promarged 9y agoI think except the cryptography there is just trust calculations and encoding. These two articles describe trust in detail: https://www.linux.com/learn/pgp-web-trust-core-concepts-behind-trusted-communication https://www.linux.com/learn/pgp-web-trust-core-concepts-behi... https://www.linuxfoundation.org/blog/pgp-web-of-trust-delegated-trust-and-keyservers/ https://www.linuxfoundation.org/blog/pgp-web-of-trust-delega... GPG esoteric options is also a good read: https://www.gnupg.org/documentation/manuals/gnupg/GPG-Esoteric-Options.html https://www.gnupg.org/documentation/manuals/gnupg/GPG-Esoter... Besides that... the RFC itself I suppose: https://tools.ietf.org/html/rfc4880 https://tools.ietf.org/html/rfc4880
- zokier 9y ago> I wonder what do you think is complex? For me it culminates in the way gpg feels really opinionated about key management (with keyrings). Way too often (in relative terms) I end up creating a temp dir, setting GPGHOME, then setting some permissions to quiet up gpg, then importing the keys, then actually doing the thing I wanted, and finally cleaning up[1]. I have no doubt the keyring design works wonderfully for gpgs author(s), but for a tool that should really be more generic than that it feels less ideal. gpg being as monolithic as it is probably is the fundamental problem here which, in addition to making it unnecessarily cumbersome to use in some cases, also makes it more difficult to learn piecewise (imo). [1] For one example, see my comment here: https://github.com/keybase/keybase-issues/issues/2230#issuecomment-239637659 https://github.com/keybase/keybase-issues/issues/2230#issuec... That operation should be basically "curl ..|gpg-key --to-ssh", but instead it exploded into 10 line bash script, complete with parsing gpg output with grep/awk.
- JdeBP 9y agoNote that, per the blurb at hand, NeoPG is intentionally even more monolithic.