Skip to main content

Search

Items tagged with: openpgp


Working based on interoperable specifications is value to users and developers. Development teams get the freedom to exchange component implementations which is beneficial to the user. Other developers can team up to replace a whole tool or app with another interoperable one, providing a second level of "freedom to exit". Its true for #activitypub and is true for our e-mail Standards and #openpgp based end-to-end encryption. Protocols are the fundamental source to provide freedom of exit.


please don't conflate the #OpenPGP specification with GPG and don't compare crypto specs to implementations unless you are ready to say "interoperable multi-party agreed specs are bad". Fwiw we use an audited lean, pure Rust implementation to provide users "guaranteed end-to-end encryption" that is safe against compromised servers and requires no key servers at all. Here is a post about a 2024 analysis from the applied crypto team of ETH Zürich about #securejoin delta.chat/en/2024-03-25-crypt…


#Thunderbird 128.4.3 addressed a high security vulnerability in their #OpenPGP implementation

#CVE-2024-11159 Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext.

www.mozilla.org/en-US/security/advisories/mfsa2024-61/