home.social

#gnupg — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #gnupg, aggregated by home.social.

fetched live
  1. So I created a simple guide to use GNUPG. Take a look and feel free to provide any feedback (for improvements or any reviews)
    netizens-corner.neocities.org/

    Also; if think more of such simplistic guides should exist then please support me via:
    netizens-corner.neocities.org/

    #freesoftware #gnulinux #FSF #opensource #gnupg #gpg #libresoftware #encryption #privacy

  2. Einsatzbericht für Nitrokey 3A (No NFC)

    Ich habe diesen Nitrokey 3A (No NFC) als Geschenk von GNU/Linux.ch erhalten für den 5K Artikel. Am Wochenende hatte ich genug Zeit, um diesen Stick zu testen und hier nun meine Meinung.

    #Linux #Nitrokey #Thunderbird #GnuPG #Linux

    gnulinux.ch/einsatzbericht-nit

  3. Einsatzbericht für Nitrokey 3A (No NFC)

    Ich habe diesen Nitrokey 3A (No NFC) als Geschenk von GNU/Linux.ch erhalten für den 5K Artikel. Am Wochenende hatte ich genug Zeit, um diesen Stick zu testen und hier nun meine Meinung.

    #Linux #Nitrokey #Thunderbird #GnuPG #Linux

    gnulinux.ch/einsatzbericht-nit

  4. Ansible Vault sicher und komfortabel nutzen: In unserem neuen Blogbeitrag zeigt Jens Meißner, wie sich Secrets mit GnuPG verschlüsselt speichern und über den GnuPG-Agent bequem verwenden lassen – ganz ohne unverschlüsselte Passwortdateien.

    ➡️ b1-systems.de/ansible-secrets-

    #Ansible #DevOps #Linux #GnuPG

  5. Ansible Vault sicher und komfortabel nutzen: In unserem neuen Blogbeitrag zeigt Jens Meißner, wie sich Secrets mit GnuPG verschlüsselt speichern und über den GnuPG-Agent bequem verwenden lassen – ganz ohne unverschlüsselte Passwortdateien.

    ➡️ b1-systems.de/ansible-secrets-

    #Ansible #DevOps #Linux #GnuPG

  6. @jarkko Yeah, OpenPGP is so popular among users that this kind of divide is exactly what we need to further fragment PQC. #OpenPGP #PQC #GnuPG #Sequoia

  7. @jarkko Yeah, OpenPGP is so popular among users that this kind of divide is exactly what we need to further fragment PQC. #OpenPGP #PQC #GnuPG #Sequoia

  8. #GnuPG 2.5.21-freepg has been released.

    It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

    Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

    Release notes
    =============

    Noteworthy changes in version 2.5.21-freepg (2026-07-03)
    --------------------------------------------------------

    * No FreePG-specific changes.

    gitlab.com/freepg/gnupg/-/rele

    Upstream's release notes follow.

    ----

    Noteworthy changes in version 2.5.21 (2026-07-02)
    -------------------------------------------------

    * New and extended features:

    - gpg, gpgsm: Use partial file on decryption, remove on failure.
    Disable with "--compatibility-flags=no-partial-file-guard".
    [T7873]

    - gpg: Use the INT_RCP_FPR subpacket in revocation signatures.
    [T8252]

    - Create a pkgversioninfo.txt file when building using the speedo
    build system.

    * Bug fixes:

    - gpg: Fix potential use-after-free in batch key generation when
    handling the keyserver URL option. [T8277]

    - gpgsm: Fix regression in gpgsm_verify with expired certificates.
    [T8188]

    - gpgsm: Require a minimum tag length for GCM decryption.
    [rG4c7e68cf3d, CVE-2026-34182]

    - scd: Limit the size of returned APDU objects from faulty cards.
    [T8281]

    - scd: Fix condition to retrieve ATR. [rGca25a7a61b]

    - scd:openpgp: Fix regression in CHV1 retry counter byte index.
    [rG245330ebea]

    - agent: Make batch import of Kyber keys work. [T8029]

    - dirmngr: Add a validation check in get_dns_cert_standard.
    [T8303]

    - gpgconf: Raise an error on certain parse errors. [T8261]

    - Fix use of usleep in file remove function on Windows. Regression
    since 2.5.13. [rGab9ce5f5e7]

    Release-info: dev.gnupg.org/T8262

  9. #GnuPG 2.5.21-freepg has been released.

    It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

    Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

    Release notes
    =============

    Noteworthy changes in version 2.5.21-freepg (2026-07-03)
    --------------------------------------------------------

    * No FreePG-specific changes.

    gitlab.com/freepg/gnupg/-/rele

    Upstream's release notes follow.

    ----

    Noteworthy changes in version 2.5.21 (2026-07-02)
    -------------------------------------------------

    * New and extended features:

    - gpg, gpgsm: Use partial file on decryption, remove on failure.
    Disable with "--compatibility-flags=no-partial-file-guard".
    [T7873]

    - gpg: Use the INT_RCP_FPR subpacket in revocation signatures.
    [T8252]

    - Create a pkgversioninfo.txt file when building using the speedo
    build system.

    * Bug fixes:

    - gpg: Fix potential use-after-free in batch key generation when
    handling the keyserver URL option. [T8277]

    - gpgsm: Fix regression in gpgsm_verify with expired certificates.
    [T8188]

    - gpgsm: Require a minimum tag length for GCM decryption.
    [rG4c7e68cf3d, CVE-2026-34182]

    - scd: Limit the size of returned APDU objects from faulty cards.
    [T8281]

    - scd: Fix condition to retrieve ATR. [rGca25a7a61b]

    - scd:openpgp: Fix regression in CHV1 retry counter byte index.
    [rG245330ebea]

    - agent: Make batch import of Kyber keys work. [T8029]

    - dirmngr: Add a validation check in get_dns_cert_standard.
    [T8303]

    - gpgconf: Raise an error on certain parse errors. [T8261]

    - Fix use of usleep in file remove function on Windows. Regression
    since 2.5.13. [rGab9ce5f5e7]

    Release-info: dev.gnupg.org/T8262

  10. Merci rephrase, j'ai retrouvé ma passphrase #GPG 🙂

    roguedaemon.net/rephrase/
    (déjà packagé dans Debian)

    Pas merci Thunderbird qui bypasse GPG et donc ben on l'oublie la passphrase…

    #GnuPG

  11. Merci rephrase, j'ai retrouvé ma passphrase #GPG 🙂

    roguedaemon.net/rephrase/
    (déjà packagé dans Debian)

    Pas merci Thunderbird qui bypasse GPG et donc ben on l'oublie la passphrase…

    #GnuPG

  12. #GnuPG 2.4.9-freepg-1 has been released.

    It contains backported bugfixes from upstream GnuPG 2.5.x, plus all the previous FreePG patches.

    Since 31st of December last year, upstream GnuPG is no longer providing bugfix releases for the 2.4.x branch, in an attempt to encourage people to upgrade to 2.5.x. The FreePG project considers the 2.5.x branch to be experimental, primarily due to its use of non-OpenPGP algorithms by default, and is continuing to support 2.4.x by porting bugfixes from the 2.5.x and 2.2.x branches, which are both still maintained upstream.

    Release Notes
    =============

    Noteworthy changes in version 2.4.9-freepg-1 (2026-07-02)
    ---------------------------------------------------------

    - Backported several bugfixes from 2.5:

    * dirmngr: Fix a call of calloc.
    * agent: Fix the regression in pkdecrypt with TPM RSA.
    * tpm: Fix possible buffer overflow in PKDECRYPT
    * gpg: Fix armor parsing when no CRC is found.
    * gpg: Fix armored input parsing.
    * gpg: Fix handling with no CRC armor.
    * gpgsm: Require a minimum tag length for GCM decryption.
    * gpg: Fix edge case in --refresh-keys

    - Fixed several tests introduced by the "tests: add test cases for import without uid" patch.

    gitlab.com/freepg/gnupg/-/rele

  13. #GnuPG 2.4.9-freepg-1 has been released.

    It contains backported bugfixes from upstream GnuPG 2.5.x, plus all the previous FreePG patches.

    Since 31st of December last year, upstream GnuPG is no longer providing bugfix releases for the 2.4.x branch, in an attempt to encourage people to upgrade to 2.5.x. The FreePG project considers the 2.5.x branch to be experimental, primarily due to its use of non-OpenPGP algorithms by default, and is continuing to support 2.4.x by porting bugfixes from the 2.5.x and 2.2.x branches, which are both still maintained upstream.

    Release Notes
    =============

    Noteworthy changes in version 2.4.9-freepg-1 (2026-07-02)
    ---------------------------------------------------------

    - Backported several bugfixes from 2.5:

    * dirmngr: Fix a call of calloc.
    * agent: Fix the regression in pkdecrypt with TPM RSA.
    * tpm: Fix possible buffer overflow in PKDECRYPT
    * gpg: Fix armor parsing when no CRC is found.
    * gpg: Fix armored input parsing.
    * gpg: Fix handling with no CRC armor.
    * gpgsm: Require a minimum tag length for GCM decryption.
    * gpg: Fix edge case in --refresh-keys

    - Fixed several tests introduced by the "tests: add test cases for import without uid" patch.

    gitlab.com/freepg/gnupg/-/rele

  14. codeberg.org/klausman/vimmage

    I have just released vimmage: a vim plugin that uses age* for ecnrypting files. It basically works like vim-gnupg, but uses age instead.

    * age-encryption.org

    #vim #ageencryption #gnupg

  15. codeberg.org/klausman/vimmage

    I have just released vimmage: a vim plugin that uses age* for ecnrypting files. It basically works like vim-gnupg, but uses age instead.

    * age-encryption.org

    #vim #ageencryption #gnupg

  16. OpenPGP: PGP meets AusweisApp und ERV

    Governikus bietet einen Beglaubigungsdienst an. Damit kann man mit Hilfe seines neuen Personalausweises und der AusweisApp seinen öffentlichen PGP-Schlüssel signieren lassen. Wie es geht und was es bringt, erfährst Du in diesem (doch recht langen) Artikel. Außerdem spreche ich einen der größten und frustrierendsten Schmerzpunkte der digitalen Rechts- und Verwaltungswelt in Deutschland an. Zuerst zum offenbar gut gemeinten Service von Governikus. Das Angebot von Governikus ist […]

    w11.haus/947

  17. OpenPGP: PGP meets AusweisApp und ERV

    Governikus bietet einen Beglaubigungsdienst an. Damit kann man mit Hilfe seines neuen Personalausweises und der AusweisApp seinen öffentlichen PGP-Schlüssel signieren lassen. Wie es geht und was es bringt, erfährst Du in diesem (doch recht langen) Artikel. Außerdem spreche ich einen der größten und frustrierendsten Schmerzpunkte der digitalen Rechts- und Verwaltungswelt in Deutschland an. Zuerst zum offenbar gut gemeinten Service von Governikus. Das Angebot von Governikus ist […]

    w11.haus/947

  18. Psst! Hast du heute Abend noch nix vor und bist in der Gegend von #Feldkirch in #Vorarlberg unterwegs?

    Wenn du dich auch noch für Verschlüsselung interessierst, dann schau doch vorbei bei unserem Stammtisch mit Vortrag. Jede*r ist willkommen, Anmeldung nicht nötig.

    #GnuPG, Kleopatra und Email-Verschlüsselung anfänger*innen-freundlich und kompetent erklärt.
    lugv.at/stammtisch-vortrag-176

  19. Psst! Hast du heute Abend noch nix vor und bist in der Gegend von #Feldkirch in #Vorarlberg unterwegs?

    Wenn du dich auch noch für Verschlüsselung interessierst, dann schau doch vorbei bei unserem Stammtisch mit Vortrag. Jede*r ist willkommen, Anmeldung nicht nötig.

    #GnuPG, Kleopatra und Email-Verschlüsselung anfänger*innen-freundlich und kompetent erklärt.
    lugv.at/stammtisch-vortrag-176

  20. Hi,

    some may know my co-owned company g10 Code which is the driving force behind #GnuPG. This spring the company turned 25 and we took the opportunity to invite some long time friends, supporters,and contributors. Here is a short report on the event which took place on May 8th:

    gnupg.com/20260601-25-years.ht

  21. Hi,

    some may know my co-owned company g10 Code which is the driving force behind #GnuPG. This spring the company turned 25 and we took the opportunity to invite some long time friends, supporters,and contributors. Here is a short report on the event which took place on May 8th:

    gnupg.com/20260601-25-years.ht

  22. The May #GNU Spotlight by Amin Bandali is now available! Read it here: u.fsf.org/4b9 #FSF #GnuPG #G-Golf

  23. The May #GNU Spotlight by Amin Bandali is now available! Read it here: u.fsf.org/4b9 #FSF #GnuPG #G-Golf

  24. I've been running #Tumpa CLI for a while on a few selected git repositories, where I use #yubikey for the #PGP key storage.

    github.com/tumpaproject/tumpa-

    Today I have globally replaced gpg2 with tcli and tclig in the git config. It does the job very well and is far less annoying than gpg ever was. The tcli agent is also much more nicely behaving than the gpg-agent.

    Thank you, @kushal for an excellent work on Tumpa!

    And I'm even more impressed that Tumpa even handles multiple Yubikeys plugged in in parallel. It selects the right key for the right identity and the tcli agent even caches the needed passphrase/PIN as expected. This is something which was a complete mess with GnuPG.

    #OpenPGP #gnupg #gpg #opensource #foss #oss

  25. I've been running #Tumpa CLI for a while on a few selected git repositories, where I use #yubikey for the #PGP key storage.

    github.com/tumpaproject/tumpa-

    Today I have globally replaced gpg2 with tcli and tclig in the git config. It does the job very well and is far less annoying than gpg ever was. The tcli agent is also much more nicely behaving than the gpg-agent.

    Thank you, @kushal for an excellent work on Tumpa!

    And I'm even more impressed that Tumpa even handles multiple Yubikeys plugged in in parallel. It selects the right key for the right identity and the tcli agent even caches the needed passphrase/PIN as expected. This is something which was a complete mess with GnuPG.

    #OpenPGP #gnupg #gpg #opensource #foss #oss

  26. #GnuPG 2.5.20-freepg has been released.

    It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

    Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

    Release notes
    =============

    Noteworthy changes in version 2.5.20-freepg (2026-05-15)
    --------------------------------------------------------

    * No FreePG-specific changes.

    gitlab.com/freepg/gnupg/-/rele

    Upstream's release notes follow.

    ------

    Noteworthy changes in version 2.5.20 (2026-05-13)
    -------------------------------------------------

    * New and extended features:

    - gpgsm: Implement GCM encryption. Note that decryption works
    since version 2.3.2. [T3979]

    - gpgsm: New option --attribute and server command SETATTR to
    include arbitrary signed or unsigned attributes into a signature.
    Enable only with libksba 1.7.0 or later. [T4537]

    - gpgsm: Introduce system attribute _signingCertificateV2.
    [rG0335a9cb04]

    * Bug fixes:

    - gpg: Fix wrong assertion failure which could very rarely occur
    during key signature checking. [rG693f5642f6]

    - gpg: Consider certify-only keys for revocation signature check.
    [T8196]

    - gpgsm: Fix possible double free in the CMS parser. [T8240]

    - gpgsm: Fix possible too early removal of ephemeral keys. [T8236]

    - gpgsm: Avoid emitting a final FAILURE status line if --status-fd
    is not used. [rG69c27fe377]

    - gpgsm: Fix a regression in 2.5.19 for password encrypted GCM
    data. [rG60a823c97b]

    - agent: Fix not using cache for pinentry loopback. [rGd4b608a31f]

    - agent: Fix command PUT_SECRET by saving input line. [rG1875bc185e]

    - keyboxd: Mark keys searched but not imported via LDAP correctly
    as ephemeral. [T8048]

    - scdaemon: Avoid buffer overflow with SC-HSM cards providing RSA
    keys > 2k. [T8244]

    - dirmngr: Fix uninitialized use of the dns_any union in
    dns_rr_cmp. [T8251]

    Release-info: dev.gnupg.org/T7997

  27. #GnuPG 2.5.20-freepg has been released.

    It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

    Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

    Release notes
    =============

    Noteworthy changes in version 2.5.20-freepg (2026-05-15)
    --------------------------------------------------------

    * No FreePG-specific changes.

    gitlab.com/freepg/gnupg/-/rele

    Upstream's release notes follow.

    ------

    Noteworthy changes in version 2.5.20 (2026-05-13)
    -------------------------------------------------

    * New and extended features:

    - gpgsm: Implement GCM encryption. Note that decryption works
    since version 2.3.2. [T3979]

    - gpgsm: New option --attribute and server command SETATTR to
    include arbitrary signed or unsigned attributes into a signature.
    Enable only with libksba 1.7.0 or later. [T4537]

    - gpgsm: Introduce system attribute _signingCertificateV2.
    [rG0335a9cb04]

    * Bug fixes:

    - gpg: Fix wrong assertion failure which could very rarely occur
    during key signature checking. [rG693f5642f6]

    - gpg: Consider certify-only keys for revocation signature check.
    [T8196]

    - gpgsm: Fix possible double free in the CMS parser. [T8240]

    - gpgsm: Fix possible too early removal of ephemeral keys. [T8236]

    - gpgsm: Avoid emitting a final FAILURE status line if --status-fd
    is not used. [rG69c27fe377]

    - gpgsm: Fix a regression in 2.5.19 for password encrypted GCM
    data. [rG60a823c97b]

    - agent: Fix not using cache for pinentry loopback. [rGd4b608a31f]

    - agent: Fix command PUT_SECRET by saving input line. [rG1875bc185e]

    - keyboxd: Mark keys searched but not imported via LDAP correctly
    as ephemeral. [T8048]

    - scdaemon: Avoid buffer overflow with SC-HSM cards providing RSA
    keys > 2k. [T8244]

    - dirmngr: Fix uninitialized use of the dns_any union in
    dns_rr_cmp. [T8251]

    Release-info: dev.gnupg.org/T7997

  28. Exciting news from the coalface! The first beta of Hockeypuck 2.4 with PQC support is now live on test.pgpkeys.eu for public evaluation.

    #OpenPGP is going post-quantum in 2026, and the #Hockeypuck #keyserver software is prepared to distribute post-quantum-safe OpenPGP certificates.

    Hockeypuck 2.4-beta1 supports post-quantum-safe signing and encryption algorithms based on ML-DSA-65, ML-DSA-87, ML-KEM-768, and ML-KEM-1024, each used in hybrid mode with either curve25519 or curve448 ECC. These are the mandatory and recommended algorithms from the upcoming OpenPGP PQC spec [1].

    In order to distribute the new primary (signing) keys safely, without adversely impacting older client software, they are only distributed over the HKPv2 API. Hockeypuck implements the `certs`, `index` and `prefixlog` endpoints as defined in the latest HKP draft spec [2]. These enable upload, download, and querying of PQC-enabled primary keys.

    PQC encryption subkeys using ML-KEM-768 are also distributed over the legacy HKP interface if they are attached to a v4 primary key, because these are safely ignored by #GnuPG.

    (GnuPG’s “kyber” algorithms are unfortunately not supported due to interoperability issues)

    Hockeypuck 2.4 development has been kindly supported by @NGIZero Core.

    [1] datatracker.ietf.org/doc/html/
    [2] datatracker.ietf.org/doc/html/

  29. Exciting news from the coalface! The first beta of Hockeypuck 2.4 with PQC support is now live on test.pgpkeys.eu for public evaluation.

    #OpenPGP is going post-quantum in 2026, and the #Hockeypuck #keyserver software is prepared to distribute post-quantum-safe OpenPGP certificates.

    Hockeypuck 2.4-beta1 supports post-quantum-safe signing and encryption algorithms based on ML-DSA-65, ML-DSA-87, ML-KEM-768, and ML-KEM-1024, each used in hybrid mode with either curve25519 or curve448 ECC. These are the mandatory and recommended algorithms from the upcoming OpenPGP PQC spec [1].

    In order to distribute the new primary (signing) keys safely, without adversely impacting older client software, they are only distributed over the HKPv2 API. Hockeypuck implements the `certs`, `index` and `prefixlog` endpoints as defined in the latest HKP draft spec [2]. These enable upload, download, and querying of PQC-enabled primary keys.

    PQC encryption subkeys using ML-KEM-768 are also distributed over the legacy HKP interface if they are attached to a v4 primary key, because these are safely ignored by #GnuPG.

    (GnuPG’s “kyber” algorithms are unfortunately not supported due to interoperability issues)

    Hockeypuck 2.4 development has been kindly supported by @NGIZero Core.

    [1] datatracker.ietf.org/doc/html/
    [2] datatracker.ietf.org/doc/html/

  30. Как шифровать сообщения в любом мессенджере и соцсети

    В нынешних условиях многим пользователям приходится по принуждению использовать незащищённые мессенджеры и социальные сети, то есть скомпрометированные каналы связи. К счастью, есть возможность передавать секретные зашифрованные сообщения по публичным открытым каналам. Это стандартная задача, которая давно решена в криптографии. Более того, зашифрованное сообщение можно сделать похожим на обычный текст или даже скрыть в обычном контенте — видео, звуковых файлах и тексте, который не вызовет подозрений у «цензора». Это область стеганографии Но прямо сейчас людям нужен простой и практичный способ шифровать сообщения, максимально удобным способом. Рассмотрим самые простые онлайновые утилиты, которые позволяют это делать.

    habr.com/ru/companies/globalsi

    #шифрование #Paranoia_Text_Encryption #LOCKPUB #GCHQ_CyberChef #AES_Utils #GnuPG #OpenSSL #ccrypt #VeraCrypt #Cryptomator

  31. (more Linux and FOSS news in previous posts of thread)

    Vulkan 1.4.350 Released With Three New Extensions:
    phoronix.com/news/Vulkan-1.4.3

    VideoLAN publishes dav2d, an early CPU decoder for AV2 video codec:
    videocardz.com/newz/videolan-p

    GnuPG introduces support for post-quantum crypto encryption & 64-bit Windows improvements:
    alternativeto.net/news/2026/4/

    Germany's Sovereign Tech Agency launches Sovereign Tech Standards to support open standards:
    gamingonlinux.com/2026/04/germ

    Star Labs Releases Coreboot Firmware 26.05 with New Features for Its Linux PCs:
    9to5linux.com/star-labs-releas

    More retro goodies - Microsoft open sources 86-DOS and PC-DOS:
    gamingonlinux.com/2026/04/more

    stremio v5 adds media key support, subtitle options, and HDR improvements:
    alternativeto.net/news/2026/4/

    FreeBSD 15.1 Beta Released For Early Testing:
    phoronix.com/news/FreeBSD-15.1

    #WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Vulkan #dav2d #AV2 #GnuPG #SovereignTechStandards #Coreboot #86dos #PCDOS #stremio #FreeBSD #BSD #Encryption #Privacy #Multimedia #RetroOS #OS #Firmware #FosseryTech

  32. (more Linux and FOSS news in previous posts of thread)

    Vulkan 1.4.350 Released With Three New Extensions:
    phoronix.com/news/Vulkan-1.4.3

    VideoLAN publishes dav2d, an early CPU decoder for AV2 video codec:
    videocardz.com/newz/videolan-p

    GnuPG introduces support for post-quantum crypto encryption & 64-bit Windows improvements:
    alternativeto.net/news/2026/4/

    Germany's Sovereign Tech Agency launches Sovereign Tech Standards to support open standards:
    gamingonlinux.com/2026/04/germ

    Star Labs Releases Coreboot Firmware 26.05 with New Features for Its Linux PCs:
    9to5linux.com/star-labs-releas

    More retro goodies - Microsoft open sources 86-DOS and PC-DOS:
    gamingonlinux.com/2026/04/more

    stremio v5 adds media key support, subtitle options, and HDR improvements:
    alternativeto.net/news/2026/4/

    FreeBSD 15.1 Beta Released For Early Testing:
    phoronix.com/news/FreeBSD-15.1

    #WeeklyNews #OpenSource #FOSSNews #FOSS #OpenSourceNews #News #Vulkan #dav2d #AV2 #GnuPG #SovereignTechStandards #Coreboot #86dos #PCDOS #stremio #FreeBSD #BSD #Encryption #Privacy #Multimedia #RetroOS #OS #Firmware #FosseryTech

  33. #GnuPG 2.5.19-freepg has been released.

    It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

    Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

    Release Notes
    =============

    Noteworthy changes in version 2.5.19-freepg (2026-04-30)
    -------------------------------------------------

    * No FreePG-specific changes.

    gitlab.com/freepg/gnupg/-/rele

    Upstream's release notes follow.

    -----

    Noteworthy changes in version 2.5.19 (2026-04-24)
    -------------------------------------------------

    * New and extended features:

    - gpg: New option --use-ocb-sym. [rGccdcdfbb37]

    - gpg: New options --show-[only-]session-hash. [rGecd0f7afa1]

    - gpgsm: Allow cipher mode to be part of the algo given to the
    --cipher-algo option. [T3979]

    - gpgsm: Emit more details when failing to check a crlDP. [T8221]

    - agent: Improve pinentry behavior and texts in smartcard context.
    [T6425]

    - dirmngr: New keyword "clear" for --keyserver. [rG2ab4cba36c]

    * Bug fixes:

    - gpg: Fix edge case in --refresh-keys. [T8197]

    - gpg: Don't call gcry_kdf_derive with empty passphrase. [T7739]

    - gpgsm: Skip the optional PKCS#12 PBES2 keyLength parameter to
    allow import of recently issued certificates by the German
    Telekom. [rGc8c9604bba]

    - gpgsm: Fix a bug so that a certificate can be signed using a
    different algo. [rG66fdafab3c]

    - gpgsm: Make GCM fully compliant in de-vs mode. [rG04fd775fce]

    - gpgsm: Add a certificate chain check for de-vs compliance.
    [T8188]

    - gpgsm: Show rsaPSS certificates as de-vs compliant in listings.
    [T8222]

    - agent: Rework the trustlist reading code to finally allow a
    trustlist.txt with a missing trailing LF. [T8078]

    - ssh: Fix RSA padding in signature handling. [T7882,T8202]

    - gpgtar: Fix -C (--directory) to check the output directory.
    [T8159]

    * Other changes:

    - agent: Raise an error when p >= q for RSA keys to detect
    incorrect generated *PGP keys. [T8171]

    Release-info: dev.gnupg.org/T7998

  34. #GnuPG 2.5.19-freepg has been released.

    It contains all the latest bug fixes from upstream GnuPG, plus the usual FreePG patches.

    Note that the FreePG project considers the 2.5.x branch to be experimental, and does not enable non-standard OpenPGP algorithms unless “--compliance=gnupg” is explicitly set.

    Release Notes
    =============

    Noteworthy changes in version 2.5.19-freepg (2026-04-30)
    -------------------------------------------------

    * No FreePG-specific changes.

    gitlab.com/freepg/gnupg/-/rele

    Upstream's release notes follow.

    -----

    Noteworthy changes in version 2.5.19 (2026-04-24)
    -------------------------------------------------

    * New and extended features:

    - gpg: New option --use-ocb-sym. [rGccdcdfbb37]

    - gpg: New options --show-[only-]session-hash. [rGecd0f7afa1]

    - gpgsm: Allow cipher mode to be part of the algo given to the
    --cipher-algo option. [T3979]

    - gpgsm: Emit more details when failing to check a crlDP. [T8221]

    - agent: Improve pinentry behavior and texts in smartcard context.
    [T6425]

    - dirmngr: New keyword "clear" for --keyserver. [rG2ab4cba36c]

    * Bug fixes:

    - gpg: Fix edge case in --refresh-keys. [T8197]

    - gpg: Don't call gcry_kdf_derive with empty passphrase. [T7739]

    - gpgsm: Skip the optional PKCS#12 PBES2 keyLength parameter to
    allow import of recently issued certificates by the German
    Telekom. [rGc8c9604bba]

    - gpgsm: Fix a bug so that a certificate can be signed using a
    different algo. [rG66fdafab3c]

    - gpgsm: Make GCM fully compliant in de-vs mode. [rG04fd775fce]

    - gpgsm: Add a certificate chain check for de-vs compliance.
    [T8188]

    - gpgsm: Show rsaPSS certificates as de-vs compliant in listings.
    [T8222]

    - agent: Rework the trustlist reading code to finally allow a
    trustlist.txt with a missing trailing LF. [T8078]

    - ssh: Fix RSA padding in signature handling. [T7882,T8202]

    - gpgtar: Fix -C (--directory) to check the output directory.
    [T8159]

    * Other changes:

    - agent: Raise an error when p >= q for RSA keys to detect
    incorrect generated *PGP keys. [T8171]

    Release-info: dev.gnupg.org/T7998

  35. All who use GnuPG gpg, and especially for signing git work ... give Tumpa-cli a real run and report back to @kushal ! This project works very well already, and is just a few weeks old.

    github.com/tumpaproject/tumpa-

    I did my install using cargo build --release which gets you started super easy.

    Now we just need to convince Kushal to move to a better hosting place! What do you think, @Codeberg 😁 😉

    #PGP #OpenPGP #GnuPG #gpg #git #Rust

  36. All who use GnuPG gpg, and especially for signing git work ... give Tumpa-cli a real run and report back to @kushal ! This project works very well already, and is just a few weeks old.

    github.com/tumpaproject/tumpa-

    I did my install using cargo build --release which gets you started super easy.

    Now we just need to convince Kushal to move to a better hosting place! What do you think, @Codeberg 😁 😉

    #PGP #OpenPGP #GnuPG #gpg #git #Rust

  37. What PGP Encryption Is

    Learn what PGP encryption is, how it works, which apps use it, and which email services support OpenPGP for stronger privacy in 2026.

    beitmenotyou.online/what-pgp-e

  38. صدرت نسخة GnuPG 2.5.19 الجديدة، متضمنةً توافقاً مع الإصدارات السابقة وميزات جديدة وإصلاحات للأخطاء. أبرز ما يميز هذا التحديث هو إدخال خوارزمية Kyber (ML-KEM)، التي تُمكّن التشفير المقاوم للكم، مما يعزز الأمان بشكل كبير. كما شهد التحديث تحسينات في سلوك إدخال الرمز السري للبطاقات الذكية، وتوفير معلومات مفصلة عند فشل التحقق من قوائم إلغاء الشهادات. من المهم للمستخدمين الترقية، حيث ستتوقف سلسلة 2.4 عن الدعم قريباً.

    #GnuPG #Kyber #Encryption

  39. #GnuPG 2.5.19 is now also available for Debian based #Linux distros; e.g. for #ubuntu here
    repos.gnupg.org/deb/gnupg/ques and there is a menu to select the other distros.

  40. #GnuPG 2.5.19 is now also available for Debian based #Linux distros; e.g. for #ubuntu here
    repos.gnupg.org/deb/gnupg/ques and there is a menu to select the other distros.

  41. @kushal My OpenPGP private key ist stored on my two Yubikeys. I always sign with GnuPG when I commit with git. And, I check my release tarballs and zip files before I sign them:
    codeberg.org/duxsco/gentoo-ins

    I publish information on how to fetch my public key:
    duxsco.de/my_openpgp_public_ke

    I’d love to use only sequoia-pgp, but I think this will not happen in the foreseeable future due to the use of rust and the difficulties to package sequoia-keystore due to that:
    bugs.gentoo.org/965482

    #gnupg #sequoiapgp

  42. @kushal My OpenPGP private key ist stored on my two Yubikeys. I always sign with GnuPG when I commit with git. And, I check my release tarballs and zip files before I sign them:
    codeberg.org/duxsco/gentoo-ins

    I publish information on how to fetch my public key:
    duxsco.de/my_openpgp_public_ke

    I’d love to use only sequoia-pgp, but I think this will not happen in the foreseeable future due to the use of rust and the difficulties to package sequoia-keystore due to that:
    bugs.gentoo.org/965482

    #gnupg #sequoiapgp

  43. BREAKING! GnuPG introduces quantum-resistant ML-KEM (Kyber) as encryption algorithm!

    lists.gnupg.org/pipermail/gnup

    This is great news! However, as I've been saying for a while, we should stop considering Harvest-Now-Decrypt-Later as the only thing to be immediately concerned about. The problem of signatures (Trust-Now-Forge-Later) is wrongly assumed to be way less urgent, but the reality is that rolling out a certificate migration will be extremely painful, and quantum attacks against signatures will be stealthy and of difficult attribution initially. Especially for a project like GnuPG, it's extremely important to adopt quantum-resistant signatures ASAP.

    #crypto #cryptography #PGP #GnuPG #quantum #security #privacy #cypherpunk

  44. BREAKING! GnuPG introduces quantum-resistant ML-KEM (Kyber) as encryption algorithm!

    lists.gnupg.org/pipermail/gnup

    This is great news! However, as I've been saying for a while, we should stop considering Harvest-Now-Decrypt-Later as the only thing to be immediately concerned about. The problem of signatures (Trust-Now-Forge-Later) is wrongly assumed to be way less urgent, but the reality is that rolling out a certificate migration will be extremely painful, and quantum attacks against signatures will be stealthy and of difficult attribution initially. Especially for a project like GnuPG, it's extremely important to adopt quantum-resistant signatures ASAP.

    #crypto #cryptography #PGP #GnuPG #quantum #security #privacy #cypherpunk

  45. 🎉 Breaking #news, nerds! #GnuPG has released version 2.5.19, now with a sprinkle of "post-quantum" magic dust 🪄. Apparently, they fixed some bugs and threw in a PQC algo, but don’t worry, it's still the same snore-fest as before—it’s like putting lipstick on a cryptographic pig 🐷🔐.
    lists.gnupg.org/pipermail/gnup #Quantum #Security #Release #Cryptography #Update #HackerNews #ngated

  46. 🎉 Breaking #news, nerds! #GnuPG has released version 2.5.19, now with a sprinkle of "post-quantum" magic dust 🪄. Apparently, they fixed some bugs and threw in a PQC algo, but don’t worry, it's still the same snore-fest as before—it’s like putting lipstick on a cryptographic pig 🐷🔐.
    lists.gnupg.org/pipermail/gnup #Quantum #Security #Release #Cryptography #Update #HackerNews #ngated