9 ms·
Is there a better alternative to GPG?
by akulbe 9mo ago
Is there a better alternative to GPG?
- tptacek 9mo agoEverything is better than PGP (not just GPG --- all PGP implementations). The problem with PGP is that it's a Swiss Army Knife. It does too many things. The scissors on a Swiss Army Knife are useful in a pinch if you don't have real scissors, but tailors use real scissors. Whatever it is you're trying to do with encryption, you should use the real tool designed for that task. Different tasks want altogether different cryptosystems with different tradeoffs. There's no one perfect multitasking tool. When you look at the problem that way, surprisingly few real-world problems ask for "encrypt a file". People need backup, but backup demands backup cryptosystems, which do much more than just encrypt individual files. People need messaging, but messaging is wildly more complicated than file encryption. And of course people want packet signatures, ironically PGP's most mainstream usage, ironic because it relies on only a tiny fraction of PGP's functionality and still somehow doesn't work. All that is before you get to the absolutely deranged 1990s design of PGP, which is a complex state machine that switches between different modes of operation based on attacker-controlled records (which are mostly invisible to users). Nothing modern looks like PGP, because PGP's underlying design predates modern cryptography. It survives only because nerds have a parasocial relationship with it.
- johnisgood 9mo agoNow can you give us a list of all the features of PGP and a tool that does one specific thing really well?
- akerl_ 9mo agohttps://www.latacora.com/blog/2019/07/16/the-pgp-problem/#the-answers https://www.latacora.com/blog/2019/07/16/the-pgp-problem/#th...
- johnisgood 9mo agoSaw it, not impressed, GnuPG has a lot of more features than signing and file encryption. And there are lots of tools for file encryption anyways. I have a bash function using openssh, sometimes I use croc (also uses PAKE), etc. I need an alternative to "gpg --encrypt --armor --recipient <foo>". :)
- akerl_ 9mo agoI guess we'll have to live with you being unimpressed.
- some_furry 9mo ago> I need an alternative to "gpg --encrypt --armor --recipient <foo>" That's literally age. https://github.com/FiloSottile/age https://github.com/FiloSottile/age
- johnisgood 9mo agoNo, because there is no keyring and you have to supply people's public key each time. It is not suitable for large-scale public key management (with unknown recipients), and it does not support automatic discovery, trust management. Age does NOT SUPPORT signing at all either.
- some_furry 9mo agoWhy is a keyring important to you? Would "fetch a short-lived age public key" serve your use case? If so, then an age plugin that build atop the AuxData feature in my Fediverse Public Key Directory spec might be a solution. https://github.com/fedi-e2ee/public-key-directory-specification/blob/main/Specification.md#auxiliary-data https://github.com/fedi-e2ee/public-key-directory-specificat... But either way, you shouldn't have long-lived public keys used for confidentiality. It's a bad design to do that.
- johnisgood 9mo ago
- some_furry 9mo agohttps://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/ https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/ I wrote this to answer this exact question last year.
- xeonmc 9mo agoofftopic question: as a recent dabbling reader of introductory popsci content in cryptography, I've been wondering about what are the different segmentation of expert roles in the field? e.g. in Filippo's blogpost about Age he clarified that he's not a cryptographer but rather a cryptography engineer, is that also what your role is, what are the concrete divisions of labor, and what other related but separate positions exists in the overall landscape? where is the cutoff point of "don't roll your own crypto" in the different levels of expertise?
- johnisgood 9mo agoYou did not ask me, but you should do your due diligence because there are way too many armchair cryptographers around here.
- some_furry 9mo agoMy job title is in the Security Engineer family. I do not have a Ph.D in Cryptography (not even an honorary one), so I do not call myself a Cryptographer. (Though I sometimes use "Cryptografur" in informal contexts for the sake of the pun.)
- xeonmc 9mo agoInteresting. In a general sense, where does it fall on the xkcd#435 scale?
- pseudohadamard 9mo agoWhat you actually want doing crypto is a security engineer, not a cryptographer. To quote Shamir's Law, "cryptography is bypassed, not attacked". No-one ever attacks the crypto, they attack the way it's used, so you need an experienced cryptoplumber to set it up correctly, not a cryptographer who will design a mathematically elegant whatsit and announce "there, solved!". Ideally, this person will also design the system that uses the crypto, because no matter how skilled the people on a standards committee might be their product will always be, at best, a baroque nightmare with near-infinite attack surface, at worst an unusable pile of crap. IPsec vs. Wireguard is a prime example, but there are many others.
- miki123211 9mo agoThis is exactly that, in more detail than you could possibly ever ask for: https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/ https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/
- palata 9mo ago> It survives only because nerds have a parasocial relationship with it. I really would like to replace PGP with the "better" tool, but: * Using my Yubikey for signing (e.g. for git) has a better UX with PGP instead of SSH * I have to use PGP to sign packages I send to Maven Maybe I am a nerd emotionally attached to PGP, but after a year signing with SSH, I went back to PGP and it was so much better...
- computerfriend 9mo ago> better UX with PGP instead of SSH This might be true of comparing GPG to SSH-via-PIV, but there's a better way with far superior UX: derive an SSH key from a FIDO2 slot on the YubiKey.
- palata 9mo agoI do it with FIDO2. It's inconvenient when having multiple Yubikeys (I always end up adding the entry manually with ssh-agent), and I have to touch the Yubikey everytime it signs. That makes it very annoying when rebasing a few tens of commits, for instance. With GPG it just works.
- ahlCVA 9mo agoFor what it's worth: You can set no-touch-required on a key (it's a generation-time option though).
- palata 9mo agoSure, but then it is set to no-touch for every FIDO2 interaction I have. I don't want to touch for signing, but I want to touch when using it as a passkey, for instance.
- Avamander 9mo agoUse the PIV applet for SSH and signing Git commits instead? Git supports S/MIME and SSH can use keys over PKCS#11 basically out-of-box on OSs that don't ship gpg-agent (that just interferes with SmartCard usage in general).
- josephg 9mo agoThe thing I can't get past with PGP / GPG is that it tries to work around MITM attacks by encouraging users to place their social network on the public record (via public key attestation). This is so insane to me. The whole point of using cryptography is to keep private information private. Its hard to think of ways PGP could fail more as a security / privacy tool.
- upofadown 9mo agoDo you mean keyservers? Keyservers have nothing to do with the identity verification required to prevent MITM attacks. There is only one method available for PGP. Comparison of key fingerprints/IDs. Keyservers are simply a convenient way to get a public key (identity). Most people don't have to use them.
- benchloftbrunch 9mo agoWhat is the alternative to PGP for the specific use case of secure email? That doesn't mandate dealing with the X509 certificate bureaucracy?
- tptacek 9mo agoDon't encrypt email. https://www.latacora.com/blog/2020/02/19/stop-using-encrypted-email/ https://www.latacora.com/blog/2020/02/19/stop-using-encrypte...
- teddyh 9mo agoThe only alternative suggested by the linked article is giving up email completely in favor of centralized solutions like Signal. My short answer is “no”. My long answer is: <https://news.ycombinator.com/item?id=45390332 https://news.ycombinator.com/item?id=45390332>
- tptacek 9mo agoI wrote the linked article. I don't care what secure messenger you use. But if you choose encrypted email over Signal because "centralization", you're LARPing. The first criteria for a secure messenger has to be that it is plausibly secure, and email isn't. You'd use encrypted email (for "decentralization") because you understand the cost of losing the plaintext of your message is nil. If you tell strangers to do that, without certainty that their messages are also valueless, you're committing malpractice.
- Natanael_L 9mo agoWhat's your usecase here? Internal or external messaging?
- pseudohadamard 9mo agoUse case? We're crypto LARPing dammit, we don't need a use case!
- 9mo ago
- deleted 9mo ago[deleted]
- coppsilgold 9mo agoDepending on what you are after, an alternative could be using SSH keys for signatures and age[1] for encryption targeting SSH keys. [1] <https://github.com/FiloSottile/age https://github.com/FiloSottile/age>
- baobun 9mo agosq (sequoia) is compatible and is available in your favorite distro. It's the recommended replacement. https://book.sequoia-pgp.org/about_sequoia.html https://book.sequoia-pgp.org/about_sequoia.html
- zimmerfrei 9mo agoThis is the right answer. The problem mostly concerns the oldest parts of PGP (the protocol), which gpg (the implementation) doesn't want or cannot get rid of.
- vbezhenar 9mo agoage
- lagniappe 9mo agoage https://github.com/FiloSottile/age https://github.com/FiloSottile/age
- deleted 9mo ago[deleted]