7 ms·
You can currently do the following with Kryptor: $ kryptor -e test.jpg The difference is that this uses your encryption private key. However, I will look into
by samuel-lucas6 5y ago
You can currently do the following with Kryptor:
$ kryptor -e test.jpg
The difference is that this uses your encryption private key. However, I will look into just supporting -p because that's a fair point, although that would be trickier to implement.
As for the unusable statement, I'm referring to the long list of other commands, which is more linked to digital signatures than encryption. For instance, there are entire guides and hour long YouTube videos on how to use GPG.
Edit: I've reworded my criticisms of GPG to clarify that it's not universally difficult to use.
- e12e 5y agoThis is all without any kind of key management? No web of trust, no certificate authority/repository? Gpg is hardly perfect - but I'm not sure how useful public key signature and authenticated encryption modes are without key management? Are there any kind of embedded timestamp for signatures and encrypted files (signed at/valid to etc)? Ed: I gather the main focus of this project is to extend age with minisign - but I worry that what's really needed is a (new, not PGP) standard format - that allows authenticated encryption and signing - and possibly with date/validity for signatures (beyond merely an ad hoc use of minisign trusted comments - a standardized use of minisign comments might be fine?). At any rate, I'm not too thrilled about the age projects stand on signatures: https://github.com/FiloSottile/age/issues/51 https://github.com/FiloSottile/age/issues/51 I strongly believe one of the main uses of encryption is enabling trust - and that implies trusted keys, trusted content and trusted signatures - along with a notion of time. They might be constructed out of primitives - but a user facing cli/gui should probably be strongly opinionated, and have good training wheels to make misuse and misunderstanding as difficult as possible..
- samuel-lucas6 5y agoThat's correct. I've done something similar to Minisign. Handling that sort of problem is way beyond what one person can manage anyway. I'm only a student and not even a computer science student. The recommended way of sharing keys is via social media, GitHub, your website, etc. Unfortunately, Keybase has now been abandoned and was acquired by Zoom, so that's not worth using anymore. However, I don't personally see how this method of sharing is that problematic. I think it does the job sufficiently. There are no timestamps for signing or encryption, but as you mentioned, you could use the comment functionality to add a timestamp for signatures. A new standard format would be ideal, but that's probably not going to happen for a long time. I'm also disappointed by the stance on signatures, although there are several other things that are wrong with age, which is why I decided to make my own tool, not that it's perfect by any means either. I like to think I did a much better job documenting things though.
- zikduruqe 5y ago> Unfortunately, Keybase has now been abandoned and was acquired by Zoom, so that's not worth using anymore. However, I don't personally see how this method of sharing is that problematic. https://keys.pub https://keys.pub has been trying to solve this too for some time.
- rodolphoarruda 5y agoCould you please provide evidence on Keybase "abandonment" by Zoom? I'm asking because I'm a heavy user and have always been concerned about a possible sunset for the product.
- detaro 5y agocan you spot when they were bought in this graph? https://github.com/keybase/client/graphs/contributors https://github.com/keybase/client/graphs/contributors
- FabHK 5y agoWow. That is astonishing and disheartening. I had high hopes for Keybase.
- rodolphoarruda 5y agoThanks for sharing the link, even though it gives me such a bad feeling. I really like Keybase. An important part of my workflow relies on it. So... oh shit.