Ok so, I was thinking of learning more about gpg. So I did my usual, open gpg manual on one page and the arch wiki on another one. But this time, it seems like each tab showed a different side of some sort of scorched earth battle for our security.
As far as I get it, Arch runs gpg-agent on systemd with `ExecStart=/usr/bin/gpg-agent --supervised`. This `--suprvised` flag doesn't exist on the gpg manual, and instead a `--deprecated-supervised` is documented. Aparently the gpg people don't want to support socket/service activation a la systemd. Which sure, fair enough, but this started a particularly funny attrition war in which the systemd-pilled vendors are arguing for "sandbox-based security" and to keep using the deprecated flag for the forseable future, and upstream devs are arguing for "security by simplicity" to avoid supporting the feature. All of this on a cryptography library mind you. I can almost taste the irony, and it is salty my friends.
On top of that, there are the one-sided comments on arch side, such as "Warning: GnuPG started out as an implementation of the OpenPGP format. However, in recent years its maintainer has actively diverged from the OpenPGP standardization effort and is separately extending the format in a GnuPG specific way."
And on top of that, none of those sources are particularly light reading.
So, I have things to do today, and I can't afford to make my own opinion on this topic. Would someone who has been eating popcorn on this topic for some time please share with me their well crafted takes on the matter? And maybe some predictions for the future? Any drama free openpgp implementation to use instead?
If this were a "futures exchange market", how much money would you bet on "arch blinks first"?
[link] [comments]
SOCIAL SHARE CARD GENERATOR