Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The same with "GnuPG is bad" mantra on hackernews. There is nothing better that GPG currently for all its functionality and the only answer you get when asking for substitute is don't use this function or use some obscure application. Yeah right.


I agree that there is nothing better than GPG for the narrow scope of encrypting email. But I think there are very few cases where encrypted email is the most secure way to communicate, in lieu of other forms of encryption.


Encrypted email is almost a marginal usage scenario for GPG compared to other uses. It does everything. It is everywhere.Yes it is big, nobody has to use all of it. Just like C++... oh wait it is unpopular on hacker news bubble too despite being a juggernaut of a language. It will still be relevant long after hacker news will be no more.


I basically use GPG for one thing, at this point: signing git commits.

As far as I know, there isn't another GitHub/GitLab compatible way to do this. So I'll keep using GPG until there is.


Age is demonstrably better: https://github.com/FiloSottile/age

Also, an informed analysis of PGP: https://latacora.micro.blog/2019/07/16/the-pgp-problem.html


Informed analysis like lack of forward secrecy in something made for non ephemeral communication - for storing, sending files, digital signatures etc. Or backwards compatibility so you can access and verify your backups, archives etc. from 10 or more years ago.

Show me ephemeral encryption scheme for something that needs to be readable in the future like that.

This analysis is highly uninformed I would say.


It’s not an informed analysis, or even an analysis at all.

That’s not how analyzing algorithms or programs work. Even a basic threat model is missing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: