#endtoendcrypto — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #endtoendcrypto, aggregated by home.social.
-
When looking at the changes towards the new 2.5.19 version of #GnuPG, there are many small things; like a way to use OCB for symmetric-only encryption, a few defect fixes and improvements.
Not that exciting, but maintenance of the well known #LibrePGP, OpenPGPv4 and CMS capable crypto engine.... you may want to know anyhow. ;)
https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html
https://dev.gnupg.org/T7998 -
When looking at the changes towards the new 2.5.19 version of #GnuPG, there are many small things; like a way to use OCB for symmetric-only encryption, a few defect fixes and improvements.
Not that exciting, but maintenance of the well known #LibrePGP, OpenPGPv4 and CMS capable crypto engine.... you may want to know anyhow. ;)
https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html
https://dev.gnupg.org/T7998 -
Dear GnuPG packagers and builders, please upgrade libgcrypt to v1.12.2 to remove a denial of service vulnerability (estimated CVSS 3.1: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H -- 7.5 (HIGH)) Releases of other stable versions of libgcrypt are available as well.
(GnuPG versions >= 2.5.7 are not affected due to the use of a different encryption API.)
See https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html for details.
-
Dear GnuPG packagers and builders, please upgrade libgcrypt to v1.12.2 to remove a denial of service vulnerability (estimated CVSS 3.1: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H -- 7.5 (HIGH)) Releases of other stable versions of libgcrypt are available as well.
(GnuPG versions >= 2.5.7 are not affected due to the use of a different encryption API.)
See https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html for details.
-
Details about the (ongoing) response to https://gpg.fail/ from GnuPG's side:
* https://www.gnupg.org/blog/20251226-cleartext-signatures.html
* https://dev.gnupg.org/T7906 Memory Corruption in ASCII-Armor Parsing
* https://dev.gnupg.org/T7900 (overview)
Please upgrade to GnuPG 2.5.16, 2.4.9 or #Gpg4win 5.0.0-beta479 which already have the fix for what (currently) is seen to be the only major defect: T7906.(Researchers - Thanks! - found defects in GnuPG, Sequoia-PG, Minisign and age.)
-
Details about the (ongoing) response to https://gpg.fail/ from GnuPG's side:
* https://www.gnupg.org/blog/20251226-cleartext-signatures.html
* https://dev.gnupg.org/T7906 Memory Corruption in ASCII-Armor Parsing
* https://dev.gnupg.org/T7900 (overview)
Please upgrade to GnuPG 2.5.16, 2.4.9 or #Gpg4win 5.0.0-beta479 which already have the fix for what (currently) is seen to be the only major defect: T7906.(Researchers - Thanks! - found defects in GnuPG, Sequoia-PG, Minisign and age.)
-
#GnuPG v2.5.14 is here to try.
A no-brainer upgrade for those who use the 2.5 series already. You'd get some defects fixed and a new secret key export-import for the Post quantum cryptography (#PQC) algorithm "Kyber". RCF8332 for ssh is now supported.
For others: the 2.5 series is good for Windows 64 and PQC. #LibrePGP #OpenPGPv4 #EndtoEndCrypto
https://lists.gnupg.org/pipermail/gnupg-announce/2025q4/000499.html
-
#GnuPG v2.5.14 is here to try.
A no-brainer upgrade for those who use the 2.5 series already. You'd get some defects fixed and a new secret key export-import for the Post quantum cryptography (#PQC) algorithm "Kyber". RCF8332 for ssh is now supported.
For others: the 2.5 series is good for Windows 64 and PQC. #LibrePGP #OpenPGPv4 #EndtoEndCrypto
https://lists.gnupg.org/pipermail/gnupg-announce/2025q4/000499.html
-
@fdroidorg @Tutanota the original claim was protecting data and notification patterns. So that Google and Apple cannot see them. IMAPS and SMTPS is enough for this, only the network operators and the server operators can then see notifications and the data.
If you want to do more, a standardized #endtoendcrypto solution for email is a good next step. Coming with some work. Like using OpenPGPv4/MIME (or LibrePGP/MIME, S/MIME). That protects even against the server provider to some extend.
-
@fdroidorg @Tutanota the original claim was protecting data and notification patterns. So that Google and Apple cannot see them. IMAPS and SMTPS is enough for this, only the network operators and the server operators can then see notifications and the data.
If you want to do more, a standardized #endtoendcrypto solution for email is a good next step. Coming with some work. Like using OpenPGPv4/MIME (or LibrePGP/MIME, S/MIME). That protects even against the server provider to some extend.
-
Back from the summer, #GnuPG 2.5.12 is now ready for production usage.
And this includes the post-quantum cryptography encryption (#PQC) support which is the main feature of the 2.5 series. (Okay, there is also better support for 64bit Windows.)So give it a spin or point your favourite GNU/Linux distribution to it for packaging.
https://lists.gnupg.org/pipermail/gnupg-announce/2025q3/000497.html
-
Back from the summer, #GnuPG 2.5.12 is now ready for production usage.
And this includes the post-quantum cryptography encryption (#PQC) support which is the main feature of the 2.5 series. (Okay, there is also better support for 64bit Windows.)So give it a spin or point your favourite GNU/Linux distribution to it for packaging.
https://lists.gnupg.org/pipermail/gnupg-announce/2025q3/000497.html
-
According to @ct_Magazin and the press release https://merlinux.eu/press/2025-05-14-russia-deltachat.pdf Russia sues the German company merlinux GmbH over Delta Chat, an email and #OpenPGP based #Endtoendcrypto messenger.
-
According to @ct_Magazin and the press release https://merlinux.eu/press/2025-05-14-russia-deltachat.pdf Russia sues the German company merlinux GmbH over Delta Chat, an email and #OpenPGP based #Endtoendcrypto messenger.
-
#GnuPG's "public testing release series" has a new version 2.5.7.
https://lists.gnupg.org/pipermail/gnupg-announce/2025q2/000493.html
Remember:
* It is for you, if you want to test the new
post-quantum cryptography (PQC) features
or the 64 Bit Windows support.* The series features Kyber (FIPS-203) as PQC encryption algorithm.
A new Gpg4win 5 Beta is forthcoming in the next days.
Technical details: https://dev.gnupg.org/T7671
-
#GnuPG's "public testing release series" has a new version 2.5.7.
https://lists.gnupg.org/pipermail/gnupg-announce/2025q2/000493.html
Remember:
* It is for you, if you want to test the new
post-quantum cryptography (PQC) features
or the 64 Bit Windows support.* The series features Kyber (FIPS-203) as PQC encryption algorithm.
A new Gpg4win 5 Beta is forthcoming in the next days.
Technical details: https://dev.gnupg.org/T7671
-
If you are using the PDF viewer #Okular_from #Gpg4win, please upgrade to version 4.4.1 as this version fixes a severe vulnerability in the freetype library.
:download: https://www.gpg4win.org/download.html
Vulnerability details:
https://euvd.enisa.europa.eu/enisa/EUVD-2025-6367 🛡️There are other good things in Gpg4win 4.4.1, for example
* improvements in the Outlook Add-in (GpgOL)
* a better Kleopatra
* GnuPG upgraded to v2.4.8 -
If you are using the PDF viewer #Okular_from #Gpg4win, please upgrade to version 4.4.1 as this version fixes a severe vulnerability in the freetype library.
:download: https://www.gpg4win.org/download.html
Vulnerability details:
https://euvd.enisa.europa.eu/enisa/EUVD-2025-6367 🛡️There are other good things in Gpg4win 4.4.1, for example
* improvements in the Outlook Add-in (GpgOL)
* a better Kleopatra
* GnuPG upgraded to v2.4.8 -
Better handling of certificates and public keys
with #Gpg4win v4.4.0's improved crypto manager _Kleopatra_.It also comes with #GnuPG v2.4.7 for Windows. Workflows that profit from several signatures on a file
profit as well.https://gpg4win.org/version4.4.html <-- see what else is new.
-
Better handling of certificates and public keys
with #Gpg4win v4.4.0's improved crypto manager _Kleopatra_.It also comes with #GnuPG v2.4.7 for Windows. Workflows that profit from several signatures on a file
profit as well.https://gpg4win.org/version4.4.html <-- see what else is new.
-
@DD9JN
#GnuPG 2.4.5 comes with a number of improvements,
that look small at first sight, but can be decisive
if you have the use case. Like one additional NFC reader (ACR-122U)
and one ECC card from D-Trust are supported. Or getting pubkeys
from behind a proxy is fixed. Details: https://dev.gnupg.org/T6960
MacOS build: https://lists.gnupg.org/pipermail/gnupg-users/2024-March/066993.html
#endtoendcrypto #FreeSoftware -
@DD9JN
#GnuPG 2.4.5 comes with a number of improvements,
that look small at first sight, but can be decisive
if you have the use case. Like one additional NFC reader (ACR-122U)
and one ECC card from D-Trust are supported. Or getting pubkeys
from behind a proxy is fixed. Details: https://dev.gnupg.org/T6960
MacOS build: https://lists.gnupg.org/pipermail/gnupg-users/2024-March/066993.html
#endtoendcrypto #FreeSoftware -
#Gpg4win v4.3.0 <- freshly announced.
New is that encrypted files with email structure from disk can be shown.
Kleopatra and the Outlook Add-in gain features and resilience for less common situations (like Apple mail attachments or unreliable S/MIME CRLs).
Includes #GnuPG v2.4.4 and its many improvements.
https://lists.wald.intevation.org/pipermail/gpg4win-announce/2024/000104.html
-
#Gpg4win v4.3.0 <- freshly announced.
New is that encrypted files with email structure from disk can be shown.
Kleopatra and the Outlook Add-in gain features and resilience for less common situations (like Apple mail attachments or unreliable S/MIME CRLs).
Includes #GnuPG v2.4.4 and its many improvements.
https://lists.wald.intevation.org/pipermail/gpg4win-announce/2024/000104.html
-
Look at https://gpg4win.org/version4.2.html to see why freshly released #Gpg4win 4.2.0 makes a difference: Includes an experimental, lightweight PDF reader geared towards secure environments.(To use the validation and signing abilities of the included PDF Reader #Okular by #KDE today, you'd probably need to be an expert to configure the certs. Usability is planned to improve with later releases). Gpg4win is faster for large files and with many public keys. #GnuPG 2.4.3 included. #EndtoEndCrypto #OpenPGP
-
Look at https://gpg4win.org/version4.2.html to see why freshly released #Gpg4win 4.2.0 makes a difference: Includes an experimental, lightweight PDF reader geared towards secure environments.(To use the validation and signing abilities of the included PDF Reader #Okular by #KDE today, you'd probably need to be an expert to configure the certs. Usability is planned to improve with later releases). Gpg4win is faster for large files and with many public keys. #GnuPG 2.4.3 included. #EndtoEndCrypto #OpenPGP
-
Looking into #GnuPG 2.4.3, which is available now: It is a typical small point release which fixes some minor defects and improves the performance on Windows, especially for for large files.
Noteworthy also: the default expiration time period for new public keys has been increased to 3 years and that there is a new PKCS#12 parser (yes GnuPG's gpgsm can do CMS for S/MiME ;) ).
Announcement: https://lists.gnupg.org/pipermail/gnupg-announce/2023q3/000480.html
Release Issue: https://dev.gnupg.org/T6509 -
@fsf Thanks for promoting a decentral comunication solution - email and OpenPGP with GnuPG! As for the guide,: keyservers and the web of trust have lost quite a bit of relevance in recent years. What would be really cool is to select an email provider that offers the pubkeys via the web key directory. https://wiki.gnupg.org/WKD and bring your public key up there. #GnuPG #FreeSoftware #EndtoEndCrypto
-
@fsf Thanks for promoting a decentral comunication solution - email and OpenPGP with GnuPG! As for the guide,: keyservers and the web of trust have lost quite a bit of relevance in recent years. What would be really cool is to select an email provider that offers the pubkeys via the web key directory. https://wiki.gnupg.org/WKD and bring your public key up there. #GnuPG #FreeSoftware #EndtoEndCrypto
-
Today it is to celebrate 25 years of #GnuPG 🎉 a #FreeSoftware implementation of the '#OpenPGP and #CMS standards for #endtoendcrypto . For this GnuPG 2.4.0 is announced and #Gpg4win 4.1.0, see https://lists.gnupg.org/pipermail/gnupg-announce/2022q4/000477.html and https://lists.wald.intevation.org/pipermail/gpg4win-announce/2022/000099.html
-
Today it is to celebrate 25 years of #GnuPG 🎉 a #FreeSoftware implementation of the '#OpenPGP and #CMS standards for #endtoendcrypto . For this GnuPG 2.4.0 is announced and #Gpg4win 4.1.0, see https://lists.gnupg.org/pipermail/gnupg-announce/2022q4/000477.html and https://lists.wald.intevation.org/pipermail/gpg4win-announce/2022/000099.html
-
As #GnuPG user, get v2.2.36 (LTS), v2.3.7 or a fix from your GNU/Linux distribution! There is a nasty defect when transferring the verification status of a signature to the using application. With preconditions a signature can be forged.
https://lists.gnupg.org/pipermail/gnupg-announce/2022q3/000474.html
https://lists.gnupg.org/pipermail/gnupg-users/2022-July/066122.html
There is also a new #Gpg4win v4.0.3 release. #Security #EndtoEndCrypto #FreeSoftwareFor a third party desrcription see https://ubuntu.com/security/CVE-2022-34903
-
#Gpg4win is just jumping two little numbers from 4.0.0 to 4.0.2, but there is a lot in store for users. The (expert) GUI Kleopatra got many detailed improvements and the crypto backend. See https://www.gpg4win.org/change-history.html
https://dev.gnupg.org/T5743 and https://dev.gnupg.org/T5937 for all changes. #OpenPGP #EndtoEndCrypto #FreeSoftware #CryptographicMessageSyntax -
#GnuPG LTS 2.2.34 is available. It improves ed25519 handling, which is now the default
algorithms for new keypairs in the new 2.3. generation. Also fixes an important defect
for internationalised account names on Windows. (And some other fixes.)
https://lists.gnupg.org/pipermail/gnupg-announce/2022q1/000470.html
#FreeSoftware #EndtoEndCrypto #OpenPGP -
#Gpg4win 4.0.0 is a major upgrade of the official #GnuPG build for Microsoft Windows. Coming with the modern GnuPG 2.3 line for the first time. GnuPG provides a future-ready foundation for the secure exchange of data and mails over the next years, by implementing the upcoming draft of the #OpenPGP protocol and making the switch to better default algorithms. https://www.gpg4win.org/version4.html #EndtoEndCrypto #OpenPGP #OpenStandard #FreeSoftware
-
#GnuPG 2.2.33 LTS brings a
few new options to ease user support and large scale installations (in addition of fixing a few minor problems as usual ;) ).
https://lists.gnupg.org/pipermail/gnupg-announce/2021q4/000467.html (GnuPG is a #FreeSoftware engine for #EndToEndCrypto wit email and files, it support both open standards #OpenPGP and #CryptographicMessageSyntax ) -
#GnuPG 2.2.32 (LTS) fixes an important piece of validation when using keyservers or WKD with websites that use Let's encrypt certificates. Either go to GnuPG 2.2.32 or remove an outdated intermediate certificate from Let's encrypt from your system cert store. See https://dev.gnupg.org/T5639 and https://lists.gnupg.org/pipermail/gnupg-announce/2021q4/000465.html #EndtoEndCrypto
-
Looking for #OpenPGP pub-keyservers? https://spider.pgpkeys.eu tries to list new active ones, now including those with the new hockeypuck software. Can be used with #GnuPG. (https://spider.pgpkeys.eu/graphs even has a graph). Done on a best-effort basis by https://andrewg.com, see https://lists.gnupg.org/pipermail/gnupg-devel/2021-September/034962.html #EndtoEndCrypto
-
#GnuPG 2.2.30 and 2.2.31 (LTS) mainly add support to check entered passwords against patterns. (Backported from the "news release series", it seems.)
https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000463.html
https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000464.html
#EndtoEndCrypto #FreeSoftware #EmailSecurity #FileSecurity #OpenPGP -
#GnuPG 2.2.30 and 2.2.31 (LTS) mainly add support to check entered passwords against patterns. (Backported from the "news release series", it seems.)
https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000463.html
https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000464.html
#EndtoEndCrypto #FreeSoftware #EmailSecurity #FileSecurity #OpenPGP -
Over the summer #GnuPG 2.3.2 (the new release series) pushed many smaller features further in August. Discovery of pubkeys is improved. So are the hardware tokens. Entered passwords can now be checked against patterns. https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000462.html #EndtoEndCrypto #FreeSoftware #EmailSecurity #FileSecurity #OpenPGP
-
Over the summer #GnuPG 2.3.2 (the new release series) pushed many smaller features further in August. Discovery of pubkeys is improved. So are the hardware tokens. Entered passwords can now be checked against patterns. https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000462.html #EndtoEndCrypto #FreeSoftware #EmailSecurity #FileSecurity #OpenPGP
-
#GnuPG 2.2.29 (LTS) is available. It has a few regessions from 2.2.28 fixed and changes the the default keyserver to keyserver.ubuntu.com (temporarily).
https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000461.html As you may know the old SKS keyserver network was attacked and withers out. The future is for https://wiki.gnupg.org/WKD and upcoming new keyserver software like hockeypuck. E.g. there are some candidate public keyservers you could try
https://lists.gnupg.org/pipermail/gnupg-users/2021-June/065278.html #EndtoEndCrypto #FreeSoftware #EmailSecurity #FileSecurity -
#GnuPG 2.2.29 (LTS) is available. It has a few regessions from 2.2.28 fixed and changes the the default keyserver to keyserver.ubuntu.com (temporarily).
https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000461.html As you may know the old SKS keyserver network was attacked and withers out. The future is for https://wiki.gnupg.org/WKD and upcoming new keyserver software like hockeypuck. E.g. there are some candidate public keyservers you could try
https://lists.gnupg.org/pipermail/gnupg-users/2021-June/065278.html #EndtoEndCrypto #FreeSoftware #EmailSecurity #FileSecurity -
#Gpg4win 3.1.16 can be downloaded. A mixed bag of little, but important fixes and improvements for personal and organisational use, like for encrypted files. Comes with #GnuPG 2.2.28 LTS. https://www.gpg4win.de/change-history.html https://lists.wald.intevation.org/pipermail/gpg4win-announce/2021-June/000092.html File and email #EndToEndCrypto OpenPGP/MIME and S/MIME for MS Windows #FreeSoftware
-
#Gpg4win 3.1.15 is available. Features system wide config with #GnuPG. Allows Active Directory as internal keyserver. Improvements to Outlook-Addin and to smartcard support. https://www.gpg4win.org/get-gpg4win.html https://lists.wald.intevation.org/pipermail/gpg4win-announce/2021-January/000091.html #FreeSoftware #EndToEndCrypto
-
#GnuPG v2.2.27 fixes a defect relevant for S/MIME on windows so expect a #Gpg4win release within a few days (It also has progress towards reproducable builds on windows.) https://dev.gnupg.org/T5234 #EndtoEndCrypto (GnuPG is a #FreeSoftware implementation for file and email based encryption and signatures).