Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. The #39C3 “To sign or not to sign” (https://gpg.fail) talk is excellent.

The #39C3 “To sign or not to sign” (https://gpg.fail) talk is excellent.

Geplant Angeheftet Gesperrt Verschoben Uncategorized
39c3gnupg
10 Beiträge 4 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • fluepke@chaos.socialF This user is from outside of this forum
    fluepke@chaos.socialF This user is from outside of this forum
    fluepke@chaos.social
    schrieb zuletzt editiert von
    #1

    The #39C3 “To sign or not to sign” (https://gpg.fail) talk is excellent. 👏

    IMHO: Avoid PGP altogether, especially #GnuPG. Avoid memory unsafe programming languages, wherever feasible.

    It is mind boggling, that the gpg team / g10 Code GmbH refuses to fix all vulnerabilities, given that their @bsi certification and thus their business model being at risk.

    Also goes to show, that BSI certifications are worthless. Quel surprise?

    fluepke@chaos.socialF 1 Antwort Letzte Antwort
    0
    • fluepke@chaos.socialF fluepke@chaos.social

      The #39C3 “To sign or not to sign” (https://gpg.fail) talk is excellent. 👏

      IMHO: Avoid PGP altogether, especially #GnuPG. Avoid memory unsafe programming languages, wherever feasible.

      It is mind boggling, that the gpg team / g10 Code GmbH refuses to fix all vulnerabilities, given that their @bsi certification and thus their business model being at risk.

      Also goes to show, that BSI certifications are worthless. Quel surprise?

      fluepke@chaos.socialF This user is from outside of this forum
      fluepke@chaos.socialF This user is from outside of this forum
      fluepke@chaos.social
      schrieb zuletzt editiert von
      #2

      GnuPG having opinions on #Rust: https://www.gnupg.org/blog/20250117-aheinecke-on-sequoia.html

      > In my view, GnuPG and OpenPGP are extremely mature and basically done.
      > After collectively quitting their jobs at g10 Code […] former employees […] began inventing new problems and features to justify competition [by creating sequoia]
      > *But we don't want to change*
      > At GnuPG, we understood that unnecessary changes to a secure system pose risks that in our case nearly always outweigh the benefits.

      Hey, GnuPG: You’re wrong! Grow tf up!

      neverpanic@chaos.socialN 1 Antwort Letzte Antwort
      0
      • fluepke@chaos.socialF fluepke@chaos.social

        GnuPG having opinions on #Rust: https://www.gnupg.org/blog/20250117-aheinecke-on-sequoia.html

        > In my view, GnuPG and OpenPGP are extremely mature and basically done.
        > After collectively quitting their jobs at g10 Code […] former employees […] began inventing new problems and features to justify competition [by creating sequoia]
        > *But we don't want to change*
        > At GnuPG, we understood that unnecessary changes to a secure system pose risks that in our case nearly always outweigh the benefits.

        Hey, GnuPG: You’re wrong! Grow tf up!

        neverpanic@chaos.socialN This user is from outside of this forum
        neverpanic@chaos.socialN This user is from outside of this forum
        neverpanic@chaos.social
        schrieb zuletzt editiert von
        #3

        @fluepke Not going to happen. If you want to see more instances of GnuPG trying hard to be on the wrong side of history, look up the OpenPGP vs LibrePGP shitshow.

        At least this helps make PGP less relevant, which is good.

        fluepke@chaos.socialF 1 Antwort Letzte Antwort
        0
        • neverpanic@chaos.socialN neverpanic@chaos.social

          @fluepke Not going to happen. If you want to see more instances of GnuPG trying hard to be on the wrong side of history, look up the OpenPGP vs LibrePGP shitshow.

          At least this helps make PGP less relevant, which is good.

          fluepke@chaos.socialF This user is from outside of this forum
          fluepke@chaos.socialF This user is from outside of this forum
          fluepke@chaos.social
          schrieb zuletzt editiert von
          #4

          @neverpanic I do honestly think, PGP in general and GnuPG in particular are dead by now. They’ve made mistakes, which is fine and may happen, but they had sufficient time to fix, yet didn’t. There isn’t anything to discuss about the vulns. There’s no room for “you’re holding it wrong”. Anything else than a patch is a: Please avoid our software!

          OpenPGP RFC standardization is also a mess with GnuPG refusing to adopt improvements.

          crystalmoon@chaos.socialC 1 Antwort Letzte Antwort
          0
          • fluepke@chaos.socialF fluepke@chaos.social

            @neverpanic I do honestly think, PGP in general and GnuPG in particular are dead by now. They’ve made mistakes, which is fine and may happen, but they had sufficient time to fix, yet didn’t. There isn’t anything to discuss about the vulns. There’s no room for “you’re holding it wrong”. Anything else than a patch is a: Please avoid our software!

            OpenPGP RFC standardization is also a mess with GnuPG refusing to adopt improvements.

            crystalmoon@chaos.socialC This user is from outside of this forum
            crystalmoon@chaos.socialC This user is from outside of this forum
            crystalmoon@chaos.social
            schrieb zuletzt editiert von
            #5

            @fluepke @neverpanic Are there any *widespread* alternatives nowadays? 'cause most of what I have heard is extremely niche audience or not general-purpose.

            fluepke@chaos.socialF 1 Antwort Letzte Antwort
            0
            • crystalmoon@chaos.socialC crystalmoon@chaos.social

              @fluepke @neverpanic Are there any *widespread* alternatives nowadays? 'cause most of what I have heard is extremely niche audience or not general-purpose.

              fluepke@chaos.socialF This user is from outside of this forum
              fluepke@chaos.socialF This user is from outside of this forum
              fluepke@chaos.social
              schrieb zuletzt editiert von
              #6

              @crystalmoon @neverpanic it depends™ on the use case.

              Email is fundamentally broken, because it requires third-party software for security. Signal messenger seems wide spread.

              bohwaz@mamot.frB 1 Antwort Letzte Antwort
              0
              • fluepke@chaos.socialF fluepke@chaos.social

                @crystalmoon @neverpanic it depends™ on the use case.

                Email is fundamentally broken, because it requires third-party software for security. Signal messenger seems wide spread.

                bohwaz@mamot.frB This user is from outside of this forum
                bohwaz@mamot.frB This user is from outside of this forum
                bohwaz@mamot.fr
                schrieb zuletzt editiert von
                #7

                @fluepke
                Signal is not decentralized. You can't use your own server. You are stuck with their AWS Google Azure shit stack.
                @crystalmoon @neverpanic

                fluepke@chaos.socialF 1 Antwort Letzte Antwort
                0
                • bohwaz@mamot.frB bohwaz@mamot.fr

                  @fluepke
                  Signal is not decentralized. You can't use your own server. You are stuck with their AWS Google Azure shit stack.
                  @crystalmoon @neverpanic

                  fluepke@chaos.socialF This user is from outside of this forum
                  fluepke@chaos.socialF This user is from outside of this forum
                  fluepke@chaos.social
                  schrieb zuletzt editiert von
                  #8

                  @bohwaz @crystalmoon @neverpanic widespread adoption and newbie friendly <-> ethically sourced, bio-degradable, home-grown, decentralized.

                  bohwaz@mamot.frB 1 Antwort Letzte Antwort
                  0
                  • fluepke@chaos.socialF fluepke@chaos.social

                    @bohwaz @crystalmoon @neverpanic widespread adoption and newbie friendly <-> ethically sourced, bio-degradable, home-grown, decentralized.

                    bohwaz@mamot.frB This user is from outside of this forum
                    bohwaz@mamot.frB This user is from outside of this forum
                    bohwaz@mamot.fr
                    schrieb zuletzt editiert von
                    #9

                    @fluepke
                    There is nothing more widespread than email, it's decentralized and it works. There is no reason we cannot do something widespread ethical and decentralised (and encrypted). We don't have to compromise.
                    @crystalmoon @neverpanic

                    fluepke@chaos.socialF 1 Antwort Letzte Antwort
                    0
                    • bohwaz@mamot.frB bohwaz@mamot.fr

                      @fluepke
                      There is nothing more widespread than email, it's decentralized and it works. There is no reason we cannot do something widespread ethical and decentralised (and encrypted). We don't have to compromise.
                      @crystalmoon @neverpanic

                      fluepke@chaos.socialF This user is from outside of this forum
                      fluepke@chaos.socialF This user is from outside of this forum
                      fluepke@chaos.social
                      schrieb zuletzt editiert von
                      #10

                      @bohwaz @crystalmoon @neverpanic email stopped working, when Microsoft and t-online entered the game.

                      Hosting your own mail server is hard and we shouldn’t expect anyone to host their own server.

                      The standard solution for mail encryption is S/MIME. PGP standardization is broken.

                      1 Antwort Letzte Antwort
                      1
                      0
                      • skorpy@chaos.socialS skorpy@chaos.social shared this topic
                      Antworten
                      • In einem neuen Thema antworten
                      Anmelden zum Antworten
                      • Älteste zuerst
                      • Neuste zuerst
                      • Meiste Stimmen



                      Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                      Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                      Impressum | Datenschutzerklärung | Nutzungsbedingungen

                      • Anmelden

                      • Du hast noch kein Konto? Registrieren

                      • Anmelden oder registrieren, um zu suchen
                      • Erster Beitrag
                        Letzter Beitrag
                      0
                      • Home
                      • Aktuell
                      • Tags
                      • Über dieses Forum