3 ms·
Why stick with GnuPG? I'm also interested in trying to understand why use age instead of GnuPG?
by aranw 5y ago
Why stick with GnuPG?
I'm also interested in trying to understand why use age instead of GnuPG?
- zahllos 5y agoThe main argument in favour of age is that it only does one thing: encrypting files, and does it 'well' in the sense there is no need to edit your gnupg config file to exclude all the crypto from the 90s that your version of gnupg might decide to default to. This makes things significantly simpler in terms of the code for age, which reduces the possible bugs and possible misuse. GnuPG is more versatile and tries to solve a number of (arguably, orthogonal) problems, including signing and authentication (by users and also of keys in the web of trust). This leads to more complexity, and some parts, e.g. the web of trust, can't really be described as being a success. Others, such as sign and encrypt, likely don't achieve semantic security (also the case in SMIME / CMS, and I'm not sure if this has ever been fixed) and definitely don't achieve the forward/future secrecy guarantees of say Signal. Age isn't trying to be a messenger, so it doesn't need to worry about this. It comes down to this: if you use AES-Something with GnuPG or you use ChaCha20-Poly1305 with Age, it is unlikely ever to be meaningfully broken in our lifetimes (including if you are currently 1 day old and including by quantum computers) and everything will be fine. But age will only use ChaCha20-Poly1305, and the format is pretty simple, while GnuPG can be convinced to decrypt CAST5 encrypted messages and has a much more complex format that introduces a greater risk of binary parser vulnerabilities. Age is written in Go (there's also Rage, written in Rust), whereas GnuPG is a big old ball of C, so if there are parser bugs, GnuPG is bad news and Go/Rust are likely hopefully sound.
- upofadown 5y ago>...while GnuPG can be convinced to decrypt CAST5 encrypted messages... That's not actually a problem. The problem would be if it could be convinced to encrypt CAST5 messages. Assuming that is actually a problem. Is there anything particularly wrong with CAST5 other than the block size?
- dspillett 5y ago> That's not actually a problem. The problem would be if it could be convinced to encrypt CAST5 messages. I don't disagree, but would add that if the encryption used is believed to be insufficiently secure these days all tools should warn loudly that this is the case when asked to decrypt them.
- johnisgood 5y ago> Age is written in Go (there's also Rage, written in Rust), whereas GnuPG is a big old ball of C, so if there are parser bugs, GnuPG is bad news and Go/Rust are likely hopefully sound. Well, on "written in Go" part, I remember looking at the crypto code 2-3 years ago (??), and it was full of unnecessary copies. You know the practice of using explicit_bzero, avoiding copying, and so forth? In this case neither I remember was being the followed practice (it uses GC anyways), in fact, I remember copying like no tomorrow. Correct me if I am wrong though. Regardless, languages with GC are usually a no-no. There is a chapter on it in "Cryptography Engineering: Design Principles and Practical Applications by by Bruce Schneier, Niels Ferguson, and Tadayoshi Kohno", the name of the chapter is: "Implementation Issues". It mentions Java (as not being a good language for crypto due to GC), and I think C as well. In any case, it has been a while, and I am currently tired. Feel free to correct me, of course.
- wglb 5y agoKnowing who the author is and knowing what he knows and what projects he has completed I would expect that he is quite familiar with this citation and the body of literature surrounding it.
- srer 5y ago> ...edit your gnupg config file to exclude all the crypto from the 90s... Personally, I would suggest leaving Rijndael (AES winner) in ;).
- srer 5y agoI use pass, and have no desire to move away from gpg. I think gpg still provides "pretty good" privacy, I don't see any benefit that age would afford me with pass. (There are sore points to the OpenPGP user experience, integration with mail clients among others, along with the WoT, have in practice been not great. But these are not things you would encounter with pass.)