4 ms·
> This extends at first to the Rust compiler and standard library, and the Sequoia ecosystem. By Sequoia, are they talking about replacing GnuPG with https://s
by s20n 11mo ago
> This extends at first to the Rust compiler and standard library, and the Sequoia ecosystem.
By Sequoia, are they talking about replacing GnuPG with https://sequoia-pgp.org/ https://sequoia-pgp.org/ for signature verification?
I really hope they don't replace the audited and battle-tested GnuPG parts with some new-fangled project like that just because it is written in "memory-safe" rust.
- stackghost 11mo agoWhat are the remaining use cases for GnuPG that aren't done better by specialized tools?
- Valodim 11mo agoSequoia-PGP is 8 years old at this point, their 1.0 happened half a decade ago. Meanwhile, GnuPG is well regarded for its code maturity. But it is a C codebase with nearly no tests, no CI pipeline(!!), an architecture that is basically a statemachine with side effects, and over 200 flags. In my experience, only people who haven't experienced the codebase speak positively of it.
- julian-klode 11mo agoIt's rather that GnuPG is ill-regarded for its code immaturity tbh. You don't even need to read the code base, just try to use it in a script: It exits 0 when the verification failed, it exits 1 when it passed, and you have to ignore it all and parse the output of the status fd to find the truth. It provides options to enforce various algorithmic constraints but they only work in some modes and are silently ignored in others.
- bgwalter 11mo agoGnuPG has protected Snowden and he speaks positively of it. Does Sequoia-PGP have similar credentials and who funds it?
- fastball 11mo agoOr did Rust just raise its Series A?
- Avamander 11mo agoWhen was GnuPG audited and by whom?
- julian-klode 11mo agoWe have replaced GnuPG by Sequoia in the previous Debian release.