4 ms·
Such a profoundly helpful contribution.... How about detail on why it's not better than gpg?
by seized 4y ago
Such a profoundly helpful contribution.... How about detail on why it's not better than gpg?
- masklinn 4y agoUsually the complaint is that it doesn’t do the billion things gpg does. Which is exactly why I use age, the thing’s so simple there’s no way I can fuck it up, and I can plug in an ssh pubkey straight from github.
- seized 4y agoExactly. Gpg is famously straight forward to use (/s).
- loup-vaillant 4y agoIs it even possible to be "10 times better" than GPG? I mean as far as I know GPG works, and for someone who has developed a simple & safe workflow around it, it would be hard for something else to do significantly better than that. And I say that even though I'd rather write my own file encryption tool than spend even a minute learning how to use GPG.
- d-z-m 4y ago> and for someone who has developed a simple & safe workflow around it This is the kicker. Modern versions of GPG have sane defaults, but if I were a new developer who knew nothing about encryption, I would be very scared of GPG, it's aged documentation, and multitude of encryption and signing methods. Following the wrong stackoverflow answer, or an out-of-date blog post could easily get you a GPG configuration that is insecure in the year 2023. The same cannot be said for age, it has no knobs that you can dial to an insecure setting. If you'll forgive the expression, it is "idiot proof". Like you said though, GPG works, as long as you have that safe workflow.