hko, (edited ) to rust
@hko@fosstodon.org avatar

In the past few weeks, I spent a bit of time on a set of #OpenPGP hobby projects around #rpgp (https://github.com/rpgp/rpgp/). Today I'm happy to announce:

rsop v0.1.0 (https://crates.io/crates/rsop), an early stage "stateless OpenPGP" tool based on rpgp.

Relatedly, I also released rpgpie 🦀️🔐🥧 v0.0.1 (https://crates.io/crates/rpgpie), an experimental high level OpenPGP API based on rpgp (rsop is built on top of rpgpie).

#PGP #Rust #rustlang

jwildeboer, (edited ) to unpopularopinion
@jwildeboer@social.wildeboer.net avatar

#UnpopularOpinion The current spam wave supports one of my suspicions that federated networks should be built as a web of trust, Friends of a Friend style. Open registrations invite abuse and there's only so much algorithmic stuff you can throw at that. An invitation based system is also not a perfect solution as it creates artificial scarcity. A solution somewhere in-between is needed but I am still pondering how that could look like. Will continue my thoughts as a thread starting here.

kikobar,
@kikobar@acc4e.com avatar

@lazyb0y yes, google #pgp or #gpg web of trust.

@jwildeboer

hko, (edited ) to rust
@hko@fosstodon.org avatar

I just released version 0.0.1 of the new crate https://crates.io/crates/openpgp-card-state

This crate paves the way for convenient handling of #OpenPGP card User PINs, for users whose threat model allows persisting the PIN locally on the host computer.

If a User PIN is stored, applications can obtain it via this crate, and perform cryptographic operations without prompting the user for PIN entry.

Currently org.freedesktop.Secret is supported for storage.

Thoughts are welcome!

#rust #rustlang #pgp #gnupg #gpg

fsf, to random
@fsf@hostux.social avatar

Did someone say encryption? Encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk surveillance systems. Learn more with our Email Self Defense guide: https://u.fsf.org/1df #GPG #PGP #E2E #encryption

joel, to random
@joel@fosstodon.org avatar

#K9Mail integration with #OpenKeychain #pgp stuff is kinda broken after an update to the former. The app crashes everytime I write an email, because I have draft encryption enabled

This is so sad :'c

blueghost, to email
@blueghost@mastodon.online avatar

Thunderbird is an email client with built-in support for PGP encryption.

Messages are encrypted/decrypted in the client and remain encrypted on email servers, this is client-side encryption.

Some email providers support PGP encryption server-side, this method could be vulnerable to third-party decryption of emails.

PGP: https://en.wikipedia.org/wiki/Pretty_Good_Privacy
Client side encryption: https://en.wikipedia.org/wiki/Client-side_encryption

Website: https://www.thunderbird.net
Mastodon: @thunderbird

#Thunderbird #Email #Encryption #OpenPGP #PGP

hko, to random
@hko@fosstodon.org avatar

Having decidedly too much fun playing with ancient #PGP artifacts.

Note the two version 2 public keys from 1992. They were created just over a year after Phil Zimmermann first released PGP (on 6 June 1991), deep in the crypto war era.

These keys predate the #OpenPGP name by around half a decade.

At over 31 years old, nation-state actors can definitely factor John Gilmore's RSA 1024 key today.
However, I believe the cost still exceeds a hobbyist budget even now.

freemo, to security
@freemo@qoto.org avatar

It was a very very long weekend preparing Yubikeys with pgp keys.

#yubikey #pgp #gpg #security #OpenPGP

freemo, to security
@freemo@qoto.org avatar

GPG/PGP tip: When trust-signing company keys, either from another company key or a personal key, sign it so you trust the whole company, not just the individual key. To do this use tsign and select a depth of 2 with a domain restriction that matches the company's domain. This will cause you to automatically trust all employees of the company that are trusted by the company's master key and verified without you needing to set the trust individually or verify individual identities.

#GPG #PGP #Security

Master_P_the_Gu, to random German
@Master_P_the_Gu@social.tchncs.de avatar

I'm looking for an idea:
In my @thunderbird , I sign mails for different accounts digitally using #pgp . Automatic signing is switched on.
In the options, all acc's look the same, I cannot find any stored passwords anywhere inside my TB.
For one acc, I am not asked for a passphrase, mails are signed and sent immediately.
For one other acc, I am asked for a passphrase, bot only after a long wait for the pga-dialogue to appear.
What could possibly be wrong?
Cheers!

NiemPseu, to random Dutch
@NiemPseu@mastodon.nl avatar

Na dik 15 jaar @thunderbird weer geïnstalleerd. Google #Mail en #agenda gekoppeld en #PGP sleutels geïmporteerd.

dpecos, to random
@dpecos@fosstodon.org avatar

Are you attending a #PGP / #GnuPG #signing-party? I've written a small post on how to best prepare and get ready!

Super useful as a checklist to not to forget anything!

https://danielpecos.com/2024/01/23/attending-a-pgp-gnupg-signing-party/

DM_Ronin, to privacy
@DM_Ronin@mstdn.social avatar

Wow - apparently WhatsApp's design allows to gather information on which devices the client is installed, and Meta said it's all by design https://m.opnxng.com/@TalBeerySec/hi-meta-whatsapp-with-privacy-6d646c5aa3bc

Reminds me of a story back in 2017, when a flaw in encryption was found in WA and they replied with "it's not a bug, it's a feature" - and in response, my friends and I decided to add PGP encryption to WA Web as a hackathon project :blobfoxlaugh:

#Privacy #Security #Messenger #WhatsApp #Meta #Facebook #E2EE #Encryption #OpenPGP #PGP

sergio_101, to random

Everyone talks about Bob sending Alice an encrypted message but never asks how scandalous it is.

#gpg #pgp

todb, to random

I swear to Christ every time I need to do something in #PGP I get enraged all over again.

What's the cipher algorithm that PGP private keys are encrypted with when you set password protection on private keys? Something called S2k? What the fork is that?

Just be normal PGP. Please.

fsf, to random
@fsf@hostux.social avatar

Did someone say encryption? Encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk surveillance systems. Learn more with our Email Self Defense guide: https://u.fsf.org/1df #GPG #PGP #E2E #encryption

dsfgs, to random

Esteemed I2Peers @i2p, @sadiedoreen, @social and @mark22k.

It has come to our attention that M$Windows users are without a sig file.

See https://geti2p.net/download

Or (for example) https://files.i2p-projekt.de/2.4.0/

All mirrors appear to be affected.

dsfgs,

Happy New Year esteemed I2Peers @i2p @sadiedoreen @social @mark22k.

Let's not forget that MS Windows users are unable to download #I2P with a 'sig'/'asc' file at this time. Holiday periods are typically good times for people to install and learn new, great things like I2P, PGP (#gpg4win) and possibly linux. A positive experience with #PGP can go a long way.

See prior above toot for further details if needed.

We will not tag anyone further on this issue, unless one opts-in.

@GnuPG @martijn

paulox, to random
@paulox@fosstodon.org avatar

During the migration work to the new PC I found this guide by Jordan Williams on backing up and restoring OpenPGP keys using Gnu Privacy Guard (also known as GnuPG and GPG) useful 🎉

https://www.jwillikers.com/backup-and-restore-a-gpg-key

D_70WN, to random German
@D_70WN@chaos.social avatar

Gibt es ausser Posteo.de und Mailbox.org noch vertrauenswürdige E-Mail Anbieter aus Deutschland?

Tuta(nota) und reine IMAP Anbieter scheiden komplett aus, wie alle Freemailer.

kkarhan,

@D_70WN @vegos_f06 @albigdd Glaubst doch wohl nicht, dass #POP3 davor schützt?

Das wird eh alles arxhiviert wenn nicht sogar auf vorrat gespeichert...

Ob legal oder Illegal ist den Behörden shiceeegal...

Das einzig effektive was hilft, sind #OpSec, #InfoSec, #ComSec & #ITsec:

D.h. wer konsequent #PGP/MIME nutzt und sauber Identitäten trennt dem kann ne Durchsuchung shiceegal sein!

https://mstdn.social/@kkarhan/111631190348553830

glacasa, to random French
@glacasa@dotnet.social avatar

Proton Mail versus Tuta (Tutanota) encryption

https://proton.me/blog/proton-vs-tuta-encryption

« encrypted “emails” within Tuta, which cannot extend beyond their walled garden, are not really emails at all: they are encrypted messages using a proprietary format »

#ProtonMail #Tutanota #OpenPGP #PGP #Standards

gerowen, to random
@gerowen@mastodon.social avatar

Considering upgrading my personal key from 4096 bit DSA/Elgamal to ECDSA/ED25519 . Not sure it's worth the bother, given the schism that's probably going to come to a head in the next year or two as everybody tries to agree on an open, resistant asymmetric standard.

I've had my Elgamal key for years, and I have no reason to believe it has been compromised, it's just a thought. I don't use it much other than XMPP chats and file encryption between myself and family.

esm, to random
@esm@wetdry.world avatar

I THINK THE MATRIX CHAT PROTOCOL SUCKS

kkarhan,

@hexaheximal @esm @hexaheximal @protonmail I do work on getting that part fixed...
https://github.com/KBtechnologies/PocketCrypto

In the meantime, learn / (/MIME) and/or +...

Tools like make it even easier to do so...
https://github.com/life4/enc

Just like and on Desktops or on ...

kkarhan, to chat German

A little personal post I should propably pin:

Don't sent me any links/invites to #centralized, #SingleVendor / #SingleProvider #Chat or whatever sites/services.

I WILL IGNORE THEM!

If you want to contact me, you'll find all the info you want on my profile.

To protect against #Spam, all #unencrypted messages/eMails get automatically filtered as junk on server-side.

If you want a reply, add your #Pubkey to those.

Thanks for your attention!

kkarhan,

@eatyourglory no, but that's due to #Apple and them being shitty to devs.
There are #OpenPGP / #PGP/MIME implementations for #iOS tho...

https://www.openpgp.org/software/#ios

kkarhan,

@me_the_fl00f @eatyourglory

OFC...

Personally, I'm disappointed that #Apple's own #AppleMail doesn't do #PGP/MIME, because that's some very basic feature...

kkarhan,

@eatyourglory @thunderbird @cryptoparty That's a aseriously good question, because unless #Thunderbird has #FeatureParity on #mobile and #desktop, #ThunderbirdMobile will be a #downgrade.

And Inot talking aboit the #calendar but #PGP/MIME #encryption as well!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • lostlight
  • All magazines