top | item 46403734

(no title)

derleyici | 2 months ago

Werner Koch from GnuPG recently (2025-12-26) posted this on their blog: https://www.gnupg.org/blog/20251226-cleartext-signatures.htm...

Archive link: https://web.archive.org/web/20251227174414/https://www.gnupg...

discuss

order

woodruffw|2 months ago

This feels pretty unsatisfying: something that’s been “considered harmful” for three decades should be deprecated and then removed in a responsible ecosystem.

(PGP/GPG are of course hamstrung by their own decision to be a Swiss Army knife/only loosely coupled to the secure operation itself. So the even more responsible thing to do is to discard them for purposes that they can’t offer security properties for, which is the vast majority of things they get used for.)

LtWorf|2 months ago

Well python discarded signing entirely so that's one way to solve it :)

cpach|2 months ago

GPG is indeed deprecated.

Most people have never heard of it and never used it.

Valodim|2 months ago

This doesn't explain why he decided to WONTFIX what is obviously a parser bug that allows injection of data into output through the headers.

But werner at this point has a history of irresponsible decisions like this, so it's sadly par for the course by now.

Another particularly egregious example: https://dev.gnupg.org/T4493

hendi_|2 months ago

[deleted]

derleyici|2 months ago

i wouldn't normally reply to drive-by corrections, but this is wrong.

it's the GnuPG blog on gnupg.org with multiple authors.

this is a post by Werner Koch, not his blog.