3 ms·
1. Unfortunately, the draft is progressing much slower than many people would like. This is partially because not all parties agree on the best way forward for
by nwalfield 5y ago
1. Unfortunately, the draft is progressing much slower than many people would like. This is partially because not all parties agree on the best way forward for a number of technical decisions that need to be made including AEAD. See for instance this discussion: https://mailarchive.ietf.org/arch/browse/openpgp/?gbt=1&index=fmQgRm94jhvPLEOi0J-o7A8LpkY https://mailarchive.ietf.org/arch/browse/openpgp/?gbt=1&inde...
Happily, the group was rechartered at the beginning of this year and the charter is more narrow (just a cryptographic refresh). So, I'm hopeful that we'll see a new version of OpenPGP in the near future.
2. I present some evidence that pgp is effective against powerful adversaries despite its bad UX in my blog post.
We (Sequoia PGP) are working on improving the UX. Currently we are focused on the plumbing. We have a library, which we put a lot of effort into making not only feature completely, but also safe. We spent a lot of time thinking about the API usable and how to make it secure by default. We're working our way up the stack with tools like Hagrid (which powers keys.openpgp.org) and OpenPGP CA (https://openpgp-ca.org https://openpgp-ca.org), a tool for administering in-house, federated CAs.
3. If I thought the project I was working on was doomed, I'd stop :D.
- aborsy 5y agoThanks for the clarification. It’s good news that we will see a new version soon. The current version is probably secure, but an update is still needed if only for marketing (features such as AEAD or FS have become partly selling points; they may not be relevant in some cases).