So, I am creating a new #pgp key for my #email, is "RSA" #encryption still the way to go? I noticed #GPG's default is "ECC" now
Thanks in advance!
So, I am creating a new #pgp key for my #email, is "RSA" #encryption still the way to go? I noticed #GPG's default is "ECC" now
Thanks in advance!
09.05.2025: GnuPG announces release of 2.5.6 for public testing, finalized PQC algorithms are supported.
Source: https://lists.gnupg.org/pipermail/gnupg-announce/2025q2/000492.html
PQC: https://wikipedia.org/wiki/Post-quantum_cryptography
GnuPG: https://mastodon.online/@blueghost/111974048270035570
Harvest now, decrypt later: https://mastodon.online/@blueghost/111357939714657018
Added GPG signing for my Git commits via the amazing oct-git (https://crates.io/crates/openpgp-card-tool-git) rust-implementation to my git configuration:
~ ❯ git config list
...
user.signingkey=f797370e9131bb04d2d339304a64ef24ab2463ea
gpg.program=/home/chofstede/.cargo/bin/oct-git
Now the GPG key on my Nitrokey hardware security token is used to sign commits, ensuring authenticity and integrity, yay
Example commit on Codeberg: https://codeberg.org/Larvitz/gists/commit/df87e8ca18bcaf603baa13c8c150a9950c6c2b67
Example commit on Github: https://github.com/chofstede/jmore/commit/8758c31cb64a4d0b06d6859d1247a197272226a7
Messenger: Delta Chat
Obwohl es mehr als genug Messenger gibt, überzeugt Delta Chat durch Benutzerfreundlichkeit und erprobte Technik.
I have a mini Intel Atom-powered home server in my house.
However, I’ve overlooked two things:
How do I back up data and keep it safe (from both security and quality perspectives)?
I’m still a newbie at GnuPG Privacy Guard. How do I secure the backup of my private keys?
For years now I’ve had a bit of a bee under my cap: would it be possible to unlock a Vault file with a GnuPG-compatible smart card? And what if the smart card were local and the unlocking had to be triggered remotely?
Forwarding GnuPG agent over SSH
https://jpmens.net/2025/04/04/forwarding-gnupg-agent-over-ssh/
“Unless you are using #GPG, email is not end-to-end encrypted, & the contents of a message can be intercepted & read at many points, including on Google’s email servers,” said Eva Galperin, director of #cybersecurity at the Electronic Frontier Foundation.
#NationalSecurity experts have expressed alarm over the #Trump admin’s denial that the leaked #Signal chat contained #classified information.
#porkbun has #email with @protonprivacy, really affordably. So I switched my business mail to that, and I have it all setup in #emacs! :D @daviwil is a goddamned treasure. I would not be able to setup my workflow this well without Systems Crafters! I'm happy! I feel so #secure and #cozy, and I can do #gpg for a little extra. Just don't let crazy Christians on my e-mail chains. I don't want to pull a Hegseth.
07.03.2025: GnuPG announces release of 2.5.5 for public testing, finalized PQC algorithms are supported.
Source: https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html
11.03.2025: NIST selects HQC as fifth algorithm for post-quantum encryption.
Source: https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption
PQC: https://wikipedia.org/wiki/Post-quantum_cryptography
GnuPG: https://mastodon.online/@blueghost/111974048270035570
Harvest now, decrypt later: https://mastodon.online/@blueghost/111357939714657018
I recently realized that Git commits could be made on your behalf without your consent.
This could happen because either you left your computer unlocked in a public place (or any place actually), your computer got stolen and the disk wasn't encrypted or any of those combinations.
To prevent this, Git has a "signing" mechanism that proves without any doubt that you made that commit.
It uses GPG, and with power of cryptography, it protects your work from being hacked.
@lns sorry, but no. gnupgp UX sucks so hard that even I don't get it without extensive internet searching.
And I heard horrible stuff about integration into programs, like that they need to kill the #gpg daemon regularly to make it work.
Let's rather invest our efforts into making modern alternatives like #rpgp and #rsop
https://crates.io/crates/rsop/ great.
Everybody should learn how to use GPG.
Hallo #unplugtrump, ich suche unter #ios und #ipados ein #mail program am besten #opensource mit Möglichkeit #gpg / #pgp zu verwenden.
Danke
Dringend nötig für die ganzen Telegram- und Insta-Fans in #Bremen
IT-Sicherheit für #Aktivisti: Eine umfassende Einführung
Samstag, 01.03. 12:00-18:30, Infoladen Bremen
https://fomobremen.info/events/fffd9f3e-e864-4e5a-b7dc-d5487eed992a
To those still concerned with #Proton #ProtonMail: I've been trying out Lacre (https://lacre.io), which encrypts incoming #email with your #GPG key, on #Disroot. So far it has worked fairly well! If you have an account with them, see https://disroot.org/en/blog/disnews-24.11 for enrollment, though the admin had a backlog when I requested it... And if you don't, consider trying it out! (Custom domains are available: https://disroot.org/en/perks, which I have for my main email right now.)
#TIL
Man kann den #passwortmanager #pass von https://www.passwordstore.org/ tatsächlich in knapp einer Stunde auch auf Windows zum Laufen bekommen (KAF = kids acceptance factor). Man braucht nur noch #gpg und #git und dann kann es auch schon losgehen:
https://github.com/mbos/Pass4Win#readme + https://www.gpg4win.de/download-de.html
Das Kind ist total happy, dass es die Passworte nun nicht mehr nur auf dem #iphone #ios hat Das andere hat sich für die "Passwörter" #app auf #ios entschieden. Mal sehen wie lange noch
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Good afternoon, folks! Just a quick reminder: PGP isn't dead. Sign with pride!
Signed with my GPG key: 1BBD C23D 1853 255D 6415 D2EC 814E DF85 1AAB 370E
#OpenPGP #GPG #Cybersecurity #Tech #DigitalIdentity #SignYourCode
-----BEGIN PGP SIGNATURE-----
iHUEARYIAB0WIQTHaQ+iFRwfaXx+TxhjUbpCCVDiNAUCZ7cd5gAKCRBjUbpCCVDi
NOZSAPoDPFoZXKuxya98iY6nAV6hzgOghpqF/OtOVSW4qtEdMQEA3x/jqaD4R9vo
qi89wA4Hsd4KeqwTSQxKDECesI+W8QU=
=3gty
-----END PGP SIGNATURE-----
12.02.2025: GnuPG announces release of 2.5.4 for public testing, finalized PQC algorithms are supported.
Source: https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000490.html
PQC: https://wikipedia.org/wiki/Post-quantum_cryptography
GnuPG: https://mastodon.online/@blueghost/111974048270035570
Harvest now, decrypt later: https://mastodon.online/@blueghost/111357939714657018