5 ms·
Sequoia 1.3
- signal11 5y agoGood to see this project make progress -- well done to the development team. Whatever you think about pgp, it's not going away anytime soon, and a new implementation is an opportunity to brush away some cobwebs and even improve the ecosystem[1]. [1] https://sequoia-pgp.org/holistic-approach/ https://sequoia-pgp.org/holistic-approach/
- cassepipe 5y agoAnyone has a good tutorial on how to use sq, their command line utility?
- tlamponi 5y agoIt's not a tutorial in the classic sense, but as the CLI is rather simple, and as there are examples, I'd point you at the official docs (man page like): https://docs.sequoia-pgp.org/sq/index.html https://docs.sequoia-pgp.org/sq/index.html The sub commands feel like they are pretty much self-explanatory to me, e.g., encrypt, decrypt, verify are pretty clear in what they will do, and the options for those sub-commands seem not to cryptic either to me, but that's naturally a bit opinionated. Besides that the initial release news article of the sq tool has some quick demo: https://sequoia-pgp.org/blog/2021/01/26/202101-sq-release/ https://sequoia-pgp.org/blog/2021/01/26/202101-sq-release/ What would be your use cases for sq?
- _hyn3 5y ago"seem not too cryptic" nice.
- dralley 5y agoI know they plan to relicense from GPL to MPL eventually, but I wish they would do it sooner rather than later. I don't even mind the GPL, in fact most of the code I've ever written is GPL. But there are plenty of projects for which I would prefer a different license.
- aborsy 5y agoGreat! Perhaps coincidentally, on PGP 30th birthday!
- _hyn3 5y agoNot a coincidence -- in the first paragraph! :)
- tuxxy 5y agoWith all the great encryption utilities like age[0], Signal, or Veracrypt, can anyone please tell me what the point is in using pgp anymore? It's old, it's clunky, it requires careful use to be safe. Why not use something more modern? 0. https://github.com/FiloSottile/age https://github.com/FiloSottile/age
- pama 5y agoI agree that PGP is clunky. Maybe it's just me, but I often find that modern is the opposite of safe and robust.
- tptacek 5y agoI'm not sure where that's the case, but it's certainly not the case with cryptography, where "clunky" means "mired in design decisions made before the era of authenticated cryptography". To me, "old and clunky" also tends to imply "memory unsafe", or "written in Perl so old that a pipe filter in the wrong place in the input coughs up a shell", or "better make sure nobody's name is O'Connor because that includes SQL metadata", or "lol remember temp file races". But I'm prepared to concede that there may be places where the old stuff is better than the new, and eager to hear examples.
- pama 5y agoThanks very much for the additional depth on what “old and clunky” could mean in cryptography. I am no expert in this area, and I agree that all these nightmare scenarios you mention (and many more, I’m sure) are very concerning. I prefer to use old (tested and tried) Unix/BSD tools for interactive development rather than their latest rewrites or modern GUIs. In drug design, I’d rather have a clearly understood 30-year-old assay with known failure modes rather than the latest promising experiment that may still have unknown failure modes. But generally speaking, I am a sucker for new tech and I seem to never learn to stop playing with new shiny toys. In a field with explosive growth field, like machine learning, at least I can use the benchmarks against the state of the art to help me decide how or when to advance technologies (every month or so, it seems). So.. is it worthwhile to learn to use age?
- deleted 5y ago[deleted]