lingo.lol is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for linguists, philologists, and other lovers of languages.

Server stats:

69
active users

#librepgp

0 posts0 participants0 posts today

In recent weeks, a theoretical downgrade attack against the new default encryption mode used by GnuPG 2.5 has been published. This comes two years after a theoretical downgrade attack was announced against GnuPG's new default *signature* format. Both issues have been addressed in the latest update to the official OpenPGP specification, but GnuPG has declared that it will not implement the fixes.

#gnupg #openpgp #librepgp

blog.pgpkeys.eu/security-issue

blog.pgpkeys.euA Summary of Known Security Issues in LibrePGPAn occasional blog about OpenPGP keyservers and related issues

If you use #GnuPG #GPG, and you would like to ensure interoperability with Thunderbird, you might consider to disable the use of #LibrePGP features, by using option --rfc4880 in your configuration (e.g. by adding a line with the word "rfc4880" to your gpg.conf file.)
At this time it is undecided whether future Thunderbird versions will support LibrePGP or the upcoming refresh of the #IETF #OpenPGP specification, or both, or none of them. Hopefully we'll eventually see a new universal standard.

Good writeup on the #openpgp #librepgp fork in c’t magazine (German, paywalled)

“The majority of the IETF OpenPGP working group has probably committed to the crypto-refresh draft and continues to work on finalising it.

Some members of the Open PGP community are afraid that there will be two incompatible standards in the future and it will be even more complicated for users to use PGP than it already is.”

heise.de/select/ct/2024/1/2334

heise magazineAktuell | Open Source