home.social

#pgp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pgp, aggregated by home.social.

fetched live
  1. Mein PGP-Keygenerator auf dem Weg zu Post-Quantum

    Ich möchte euch nur kurz informieren, dass Post-Quantum-Kryptografie in PGP nicht mehr allzu weit entfernt ist.

    Mit RFC 9980 wurde inzwischen der offizielle IETF-Standard für Post-Quantum-Kryptografie in OpenPGP veröffentlicht.

    ➡️ Verschlüsselung: hybride Verfahren mit ML-KEM + ECC
    ➡️ Signaturen: hybride Verfahren mit ML-DSA + EdDSA

    Jetzt fehlt im Wesentlichen noch die entsprechende Umsetzung in OpenPGP.js. Sobald diese Unterstützung dort sauber integriert ist, werde ich auch meinen PGP-Keygenerator um standardkonforme Post-Quantum-OpenPGP-Schlüssel erweitern.

    :boost_ok:

    #OpenPGP #PGP #Verschlüsselung #Keygenerator #Datenschutz #Security #Secunis #ITSecurity

  2. Mein PGP-Keygenerator auf dem Weg zu Post-Quantum

    Ich möchte euch nur kurz informieren, dass Post-Quantum-Kryptografie in PGP nicht mehr allzu weit entfernt ist.

    Mit RFC 9980 wurde inzwischen der offizielle IETF-Standard für Post-Quantum-Kryptografie in OpenPGP veröffentlicht.

    ➡️ Verschlüsselung: hybride Verfahren mit ML-KEM + ECC
    ➡️ Signaturen: hybride Verfahren mit ML-DSA + EdDSA

    Jetzt fehlt im Wesentlichen noch die entsprechende Umsetzung in OpenPGP.js. Sobald diese Unterstützung dort sauber integriert ist, werde ich auch meinen PGP-Keygenerator um standardkonforme Post-Quantum-OpenPGP-Schlüssel erweitern.

    :boost_ok:

    #OpenPGP #PGP #Verschlüsselung #Keygenerator #Datenschutz #Security #Secunis #ITSecurity

  3. @dewomser

    Fast richtig, aber da werden gerade öffentlicher und privater Schlüssel verwechselt: Zum Verschlüsseln einer Mail an jemanden brauchst du dessen öffentlichen Schlüssel. Das Passwort-Feld in Mailvelope schützt dagegen normalerweise deinen privaten Schlüssel, wird zum Entschlüsseln eingehender Mails und ggf. zum Signieren gebraucht.

    Wenn du dir selbst eine verschlüsselte Mail schickst, verschlüsselt Mailvelope sie für deinen öffentlichen Schlüssel; beim Öffnen fordert es dann die Passphrase deines privaten Schlüssels an. Das ist also erwartetes Verhalten, kein Hinweis darauf, dass mit öffentlichem Schlüssel „nichts stimmt“.

    Zum sauberen Testen würde ich zwei Mailkonten und zwei getrennte PGP-Schlüsselpaare verwenden: Konto A verschlüsselt an den öffentlichen Schlüssel von Konto B, B entschlüsselt mit seinem privaten Schlüssel und antwortet umgekehrt.

    Ein zweiter Firefox-Tab ist dafür nicht wirklich getrennt. Auch Multi-Account-Container oder ein privates Fenster können je nach Erweiterungs- und Profilspeicher zu Überschneidungen führen.

    Am besten: ein zweites Firefox-Profil oder gleich ein anderer Browser, jeweils mit einer eigenen Mailvelope-Installation und nur dem passenden privaten Schlüssel.

    Wichtig beim Test: Den öffentlichen Schlüssel des jeweils anderen importieren und Fingerprints über einen zweiten Kanal vergleichen. Dann sieht man auch tatsächlich, ob Versand, Entschlüsselung und Signaturprüfung korrekt funktionieren.

    #nextcloud #mail #webmail #mailvelope #pgp #firefox

  4. @dewomser

    Fast richtig, aber da werden gerade öffentlicher und privater Schlüssel verwechselt: Zum Verschlüsseln einer Mail an jemanden brauchst du dessen öffentlichen Schlüssel. Das Passwort-Feld in Mailvelope schützt dagegen normalerweise deinen privaten Schlüssel, wird zum Entschlüsseln eingehender Mails und ggf. zum Signieren gebraucht.

    Wenn du dir selbst eine verschlüsselte Mail schickst, verschlüsselt Mailvelope sie für deinen öffentlichen Schlüssel; beim Öffnen fordert es dann die Passphrase deines privaten Schlüssels an. Das ist also erwartetes Verhalten, kein Hinweis darauf, dass mit öffentlichem Schlüssel „nichts stimmt“.

    Zum sauberen Testen würde ich zwei Mailkonten und zwei getrennte PGP-Schlüsselpaare verwenden: Konto A verschlüsselt an den öffentlichen Schlüssel von Konto B, B entschlüsselt mit seinem privaten Schlüssel und antwortet umgekehrt.

    Ein zweiter Firefox-Tab ist dafür nicht wirklich getrennt. Auch Multi-Account-Container oder ein privates Fenster können je nach Erweiterungs- und Profilspeicher zu Überschneidungen führen.

    Am besten: ein zweites Firefox-Profil oder gleich ein anderer Browser, jeweils mit einer eigenen Mailvelope-Installation und nur dem passenden privaten Schlüssel.

    Wichtig beim Test: Den öffentlichen Schlüssel des jeweils anderen importieren und Fingerprints über einen zweiten Kanal vergleichen. Dann sieht man auch tatsächlich, ob Versand, Entschlüsselung und Signaturprüfung korrekt funktionieren.

    #nextcloud #mail #webmail #mailvelope #pgp #firefox

  5. PGP-Keygenerator – lokal, transparent und sicher

    Anbieter wie Posteo oder @mailbox_org unterstützen Ende-zu-Ende-Verschlüsselung sowie die zusätzliche Verschlüsselung des Postfachs mit eigenen PGP-Schlüsseln. Mein Generator erstellt das Schlüsselpaar vollständig lokal im Browser – einfach, sicherheitsorientiert und ohne Terminal-Gehopse für alle nutzbar.

    Mir persönlich sind dabei vor allem Flexibilität und die selbstbestimmte Kontrolle über die eigenen Schlüssel wichtig. So lässt sich die zusätzliche Verschlüsselung unabhängig vom jeweiligen Anbieter einrichten, während der private Schlüssel in eigener Hand bleibt.

    Dabei habe ich unter anderem folgende Sicherheitsmaßnahmen umgesetzt:

    ✅ Vollständig clientseitige Schlüsselerzeugung und -verarbeitung
    ✅ Keine Übertragung eingegebener Daten oder erzeugter Schlüssel
    ✅ Keine dauerhafte Speicherung sensibler Daten
    ✅ Keine zusätzlichen Netzwerkverbindungen nach dem Laden
    ✅ Lokale Einbindung von OpenPGP.js und JSZip.js
    ✅ SHA-256-Integritätsprüfung der Bibliotheken mittels SRI
    ✅ Nutzung nativer kryptografischer Browserfunktionen
    ✅ Passwortschutz des privaten Schlüssels mit mindestens 16 Zeichen
    ✅ Validierung von E-Mail-Adresse, Passwort, Schlüsseltyp und Gültigkeitsdauer
    ✅ Unterstützung starker RSA- und ECC-Schlüsselprofile
    ✅ Ermittlung von Fingerprint und Long Key ID direkt aus dem öffentlichen Schlüssel
    ✅ Best-Effort-Überschreibung sensibler Eingaben beim sicheren Zurücksetzen
    ✅ Bereinigung temporärer Schlüsselobjekte und privater OpenPGP-Parameter
    ✅ Warnung und automatische Bereinigung beim Verlassen der Seite
    ✅ Schutz vor wiederhergestellten sensiblen Daten aus dem Back-Forward-Cache
    ✅ Restriktive Content Security Policy ohne externe Verbindungen
    ✅ Schutz vor Clickjacking, MIME-Sniffing und Referrer-Weitergabe
    ✅ HTTPS-Erzwingung mittels HSTS
    ✅ Zugriffsschutz für versteckte, interne und temporäre Dateien

    🔗 secunis.de/pgp-keygenerator/

    :boost_ok:

    #Datenschutz #PGP #EMail #Encryption #Posteo #Mailbox

  6. PGP-Keygenerator – lokal, transparent und sicher

    Anbieter wie Posteo oder @mailbox_org unterstützen Ende-zu-Ende-Verschlüsselung sowie die zusätzliche Verschlüsselung des Postfachs mit eigenen PGP-Schlüsseln. Mein Generator erstellt das Schlüsselpaar vollständig lokal im Browser – einfach, sicherheitsorientiert und ohne Terminal-Gehopse für alle nutzbar.

    Mir persönlich sind dabei vor allem Flexibilität und die selbstbestimmte Kontrolle über die eigenen Schlüssel wichtig. So lässt sich die zusätzliche Verschlüsselung unabhängig vom jeweiligen Anbieter einrichten, während der private Schlüssel in eigener Hand bleibt.

    Dabei habe ich unter anderem folgende Sicherheitsmaßnahmen umgesetzt:

    ✅ Vollständig clientseitige Schlüsselerzeugung und -verarbeitung
    ✅ Keine Übertragung eingegebener Daten oder erzeugter Schlüssel
    ✅ Keine dauerhafte Speicherung sensibler Daten
    ✅ Keine zusätzlichen Netzwerkverbindungen nach dem Laden
    ✅ Lokale Einbindung von OpenPGP.js und JSZip.js
    ✅ SHA-256-Integritätsprüfung der Bibliotheken mittels SRI
    ✅ Nutzung nativer kryptografischer Browserfunktionen
    ✅ Passwortschutz des privaten Schlüssels mit mindestens 16 Zeichen
    ✅ Validierung von E-Mail-Adresse, Passwort, Schlüsseltyp und Gültigkeitsdauer
    ✅ Unterstützung starker RSA- und ECC-Schlüsselprofile
    ✅ Ermittlung von Fingerprint und Long Key ID direkt aus dem öffentlichen Schlüssel
    ✅ Best-Effort-Überschreibung sensibler Eingaben beim sicheren Zurücksetzen
    ✅ Bereinigung temporärer Schlüsselobjekte und privater OpenPGP-Parameter
    ✅ Warnung und automatische Bereinigung beim Verlassen der Seite
    ✅ Schutz vor wiederhergestellten sensiblen Daten aus dem Back-Forward-Cache
    ✅ Restriktive Content Security Policy ohne externe Verbindungen
    ✅ Schutz vor Clickjacking, MIME-Sniffing und Referrer-Weitergabe
    ✅ HTTPS-Erzwingung mittels HSTS
    ✅ Zugriffsschutz für versteckte, interne und temporäre Dateien

    🔗 secunis.de/pgp-keygenerator/

    :boost_ok:

    #Datenschutz #PGP #EMail #Encryption #Posteo #Mailbox

  7. This article is a good summary of the benefits and limits of #AutoCrypt, as a Trust-On-First-Use way of using PGP to encrypt email;

    "Autocrypt does not claim to defend against it [machine-in-the-middle attacks]. What it does claim is to defend against the far more common passive adversary who simply reads mail in transit or at rest, and to do so for the vast population that would otherwise use no encryption whatsoever.

    @[email protected], 2026

    havenmessenger.com/blog/posts/

    #Haven #TOFU #PGP #email

  8. This article is a good summary of the benefits and limits of #AutoCrypt, as a Trust-On-First-Use way of using PGP to encrypt email;

    "Autocrypt does not claim to defend against it [machine-in-the-middle attacks]. What it does claim is to defend against the far more common passive adversary who simply reads mail in transit or at rest, and to do so for the vast population that would otherwise use no encryption whatsoever.

    @[email protected], 2026

    havenmessenger.com/blog/posts/

    #Haven #TOFU #PGP #email

  9. Been ruminating on this for a while and finally sat down and coded it. For some pages on my site there's now a footer that allows you to download the Markdown file and a #GPG signature of that page.

    Remembering the words of an old nerd when I started signing all my emails with #PGP on a mailing list: "Why would you _voluntarily_ give up plausible deniability on everything you write?" it won't be every page.

    But from time to time it may come in useful.

    Check it out:

    vees.net/contact/

  10. Been ruminating on this for a while and finally sat down and coded it. For some pages on my site there's now a footer that allows you to download the Markdown file and a #GPG signature of that page.

    Remembering the words of an old nerd when I started signing all my emails with #PGP on a mailing list: "Why would you _voluntarily_ give up plausible deniability on everything you write?" it won't be every page.

    But from time to time it may come in useful.

    Check it out:

    vees.net/contact/

  11. Yay! We can now send and receive both OMEMO versions! It only took, like, three days to exchange basic text messages via #xmpp, using an already developed library. On the other hand, we now have a really solid base for...the nine billion other things we need to do. At some point I'm going to want interop testing volunteers who use conversations and gajim, because those clients aren't #accessible so I can't make sure they work. But that'll probably be in a few months. Also, TIL I learned that there's really no good C# library to do #PGP. So I'm not.
  12. Yay! We can now send and receive both OMEMO versions! It only took, like, three days to exchange basic text messages via #xmpp, using an already developed library. On the other hand, we now have a really solid base for...the nine billion other things we need to do. At some point I'm going to want interop testing volunteers who use conversations and gajim, because those clients aren't #accessible so I can't make sure they work. But that'll probably be in a few months. Also, TIL I learned that there's really no good C# library to do #PGP. So I'm not.
  13. If it's possible for a user to send an unencrypted message across the wire on your "end-to-end encrypted" app, then it's not actually E2EE.

    - This means that email can't be E2EE (because a user could easily hit reply without encrypting, accidentally sending the full conversation thread in plaintext).

    - It refers to RCS texting, where, at least on Android, it will often drop down into unencrypted SMS when the RCS protocol is having trouble.

    - It's the case for Matrix even, where E2EE is a setting that can switch on or off.

    In no world would we accept an application as being encrypted between client and server if it was possible for packages to get sent in plaintext occasionally. We wouldn't put up with HTPPS occasionally sending HTML forms over HTTP on accident. Why do many people feel comfortable with the same issue when applied between two users, instead of a user and a server?

    If it's possible to send a plaintext message in an E2EE platform, then the platform isn't really E2EE.

    #encryption #security #privacy #email #pgp

  14. If it's possible for a user to send an unencrypted message across the wire on your "end-to-end encrypted" app, then it's not actually E2EE.

    - This means that email can't be E2EE (because a user could easily hit reply without encrypting, accidentally sending the full conversation thread in plaintext).

    - It refers to RCS texting, where, at least on Android, it will often drop down into unencrypted SMS when the RCS protocol is having trouble.

    - It's the case for Matrix even, where E2EE is a setting that can switch on or off.

    In no world would we accept an application as being encrypted between client and server if it was possible for packages to get sent in plaintext occasionally. We wouldn't put up with HTPPS occasionally sending HTML forms over HTTP on accident. Why do many people feel comfortable with the same issue when applied between two users, instead of a user and a server?

    If it's possible to send a plaintext message in an E2EE platform, then the platform isn't really E2EE.

    #encryption #security #privacy #email #pgp

  15. Nach langer Zeit habe ich mich nochmal mit E-Mail-Verschlüssel beschäftigt. Ich bin erstaunt, wie unproblematisch das mittlerweile in @thunderbird und bei meinem E-Mail-Provider @mailbox_org funktioniert.
    Nutzt ihr Ende-zu-Ende-Verschlüsselung bei E-Mails?

    #pgp #openpgp #email #verschlusselung #datensicherheit #security

  16. Nach langer Zeit habe ich mich nochmal mit E-Mail-Verschlüssel beschäftigt. Ich bin erstaunt, wie unproblematisch das mittlerweile in @thunderbird und bei meinem E-Mail-Provider @mailbox_org funktioniert.
    Nutzt ihr Ende-zu-Ende-Verschlüsselung bei E-Mails?

    #pgp #openpgp #email #verschlusselung #datensicherheit #security

  17. 🔐 Neues Update für meinen PGP-Keygenerator

    Version v1.1.2 → Version v1.2.0

    ✅ Neue Brainpool-Schlüsseltypen: P256r1 und P512r1
    ✅ Neue NIST-Schlüsseltypen: P-384 und P-521
    ✅ Auswahl der Schlüsselgültigkeit: 1, 2, 3 oder 5 Jahre
    ✅ „Kein Ablaufdatum“ bleibt als Standard verfügbar

    ➡️ secunis.de/pgp-keygenerator.ht

    :boost_ok:

    #OpenPGP #PGP #Datenschutz #Verschlüsselung #ITSecurity #OpenSource #Secunis

  18. 🔐 Neues Update für meinen PGP-Keygenerator

    Version v1.1.2 → Version v1.2.0

    ✅ Neue Brainpool-Schlüsseltypen: P256r1 und P512r1
    ✅ Neue NIST-Schlüsseltypen: P-384 und P-521
    ✅ Auswahl der Schlüsselgültigkeit: 1, 2, 3 oder 5 Jahre
    ✅ „Kein Ablaufdatum“ bleibt als Standard verfügbar

    ➡️ secunis.de/pgp-keygenerator.ht

    :boost_ok:

    #OpenPGP #PGP #Datenschutz #Verschlüsselung #ITSecurity #OpenSource #Secunis

  19. 🔐 PGP encryption is one of the best ways to protect your communication, but many people think it's too complicated.

    It doesn't have to be.

    We've explained PGP in a simple, easy to understand way, so anyone can grasp the basics.

    Read it here:
    novacustom.com/knowledge-base/

    #PGP #Privacy #Encryption #OpenSource #OwnYourTech

  20. 🔐 PGP encryption is one of the best ways to protect your communication, but many people think it's too complicated.

    It doesn't have to be.

    We've explained PGP in a simple, easy to understand way, so anyone can grasp the basics.

    Read it here:
    novacustom.com/knowledge-base/

    #PGP #Privacy #Encryption #OpenSource #OwnYourTech

  21. RE: digitalcourage.social/@echo_pb

    "As a result, mass scanning is now permitted again until 2028."

    "A symbolic exemption was adopted for encrypted communications"

    "The fact that Chat Control is moving forward against the will of the majority of voting MEPs is a farce and damages democracy."

    "Blanket chat control is just as unacceptable as indiscriminately opening everyone’s physical mail."

    #chatcontrol #pgp #gpg

  22. RE: digitalcourage.social/@echo_pb

    "As a result, mass scanning is now permitted again until 2028."

    "A symbolic exemption was adopted for encrypted communications"

    "The fact that Chat Control is moving forward against the will of the majority of voting MEPs is a farce and damages democracy."

    "Blanket chat control is just as unacceptable as indiscriminately opening everyone’s physical mail."

    #chatcontrol #pgp #gpg

  23. 🔐 Mein clientseitiger PGP-Keygenerator steht jetzt auch als Offline-Version zum Download bereit.

    Die Anwendung erzeugt OpenPGP-Schlüsselpaare vollständig lokal auf deinem Gerät – ohne Serverübertragung und ohne externe Verbindungen. So bleiben Passwörter und Schlüssel jederzeit unter deiner Kontrolle.

    🌐 Online:
    secunis.de/pgp-keygenerator.ht

    ⬇️ Offline-Download:
    secunis.de/downloads/pgp-keyge

    📖 Zum Artikel:
    secunis.de/clientseitiger-pgp-

    :boost_ok:

    #OpenPGP #PGP #Privacy #CyberSecurity #InfoSec #Encryption #Datenschutz #Security #Secunis

  24. RFC 9980: Post-Quantum Cryptography in OpenPGP

    Le jour où des CRQC (calculateurs quantiques capables de calculs non triviaux) seront disponibles, la cryptographie sera secouée. Il est donc important de travailler dès maintenant sur des algorithmes pour l'après-quantique, et de les intégrer dans les protocoles et les formats utilisés sur l'Internet. Ce #RFC documente l'utilisation des algorithmes NIST dans le format #OpenPGP.

    bortzmeyer.org/9980.html

    #PGP #cryptographiePostQuantique

  25. RFC 9980: Post-Quantum Cryptography in OpenPGP

    Le jour où des CRQC (calculateurs quantiques capables de calculs non triviaux) seront disponibles, la cryptographie sera secouée. Il est donc important de travailler dès maintenant sur des algorithmes pour l'après-quantique, et de les intégrer dans les protocoles et les formats utilisés sur l'Internet. Ce #RFC documente l'utilisation des algorithmes NIST dans le format #OpenPGP.

    bortzmeyer.org/9980.html

    #PGP #cryptographiePostQuantique

  26. OpenPGP: PGP meets AusweisApp und ERV

    Governikus bietet einen Beglaubigungsdienst an. Damit kann man mit Hilfe seines neuen Personalausweises und der AusweisApp seinen öffentlichen PGP-Schlüssel signieren lassen. Wie es geht und was es bringt, erfährst Du in diesem (doch recht langen) Artikel. Außerdem spreche ich einen der größten und frustrierendsten Schmerzpunkte der digitalen Rechts- und Verwaltungswelt in Deutschland an. Zuerst zum offenbar gut gemeinten Service von Governikus. Das Angebot von Governikus ist […]

    w11.haus/947

  27. OpenPGP: PGP meets AusweisApp und ERV

    Governikus bietet einen Beglaubigungsdienst an. Damit kann man mit Hilfe seines neuen Personalausweises und der AusweisApp seinen öffentlichen PGP-Schlüssel signieren lassen. Wie es geht und was es bringt, erfährst Du in diesem (doch recht langen) Artikel. Außerdem spreche ich einen der größten und frustrierendsten Schmerzpunkte der digitalen Rechts- und Verwaltungswelt in Deutschland an. Zuerst zum offenbar gut gemeinten Service von Governikus. Das Angebot von Governikus ist […]

    w11.haus/947

  28. If you include your #PGP key in your #Mastodon bio (or any social platform really), why? The only use case I have at the moment is for signing my git commits, but I'm curious if I'm missing out on something more.

    Also just discovered @keyoxide which could be anorher use. #keyoxide

    #gpg #privacy #encryption #security

  29. If you include your #PGP key in your #Mastodon bio (or any social platform really), why? The only use case I have at the moment is for signing my git commits, but I'm curious if I'm missing out on something more.

    Also just discovered @keyoxide which could be anorher use. #keyoxide

    #gpg #privacy #encryption #security

  30. Sunday Paper – PGP, Daydream VR, North Carolina and Democracy

    Filippo Valsorda: After years of wrestling with GnuPG with varying levels of enthusiasm, I came to the conclusion that it's just not worth it, and I'm giving up—at least on the concept of long-term PGP keys. This editorial is not about the gpg tool itself, or about tools at all. Many others have already written about that. It's about the long-term PGP key model—be it secured by Web of Trust, fingerprints or Trust on First Use—and how it failed me. — Filippo Valsorda Neal […]

    islandinthenet.com/reading-lis