2 ms·
Sequoia-PGP is 8 years old at this point, their 1.0 happened half a decade ago. Meanwhile, GnuPG is well regarded for its code maturity. But it is a C codebase
by Valodim 11mo ago
Sequoia-PGP is 8 years old at this point, their 1.0 happened half a decade ago.
Meanwhile, GnuPG is well regarded for its code maturity. But it is a C codebase with nearly no tests, no CI pipeline(!!), an architecture that is basically a statemachine with side effects, and over 200 flags. In my experience, only people who haven't experienced the codebase speak positively of it.
- julian-klode 11mo agoIt's rather that GnuPG is ill-regarded for its code immaturity tbh. You don't even need to read the code base, just try to use it in a script: It exits 0 when the verification failed, it exits 1 when it passed, and you have to ignore it all and parse the output of the status fd to find the truth. It provides options to enforce various algorithmic constraints but they only work in some modes and are silently ignored in others.
- bgwalter 11mo agoGnuPG has protected Snowden and he speaks positively of it. Does Sequoia-PGP have similar credentials and who funds it?