back
3 comments
If PGP is actually a bad standard from the crypto point of view I can only wonder why people downvote this and insist on supporting garbage and even rewriting it in Rust. But I'm not educated in these matters, so: what's exactly the problem with PGP/Seqouia and why age/rage are better? Can all PGP usecases be covered by age?
age only covers authenticated encryption. minisign/signify covers the signing part.

Everything else is either not used in practice or needs to be shifted to a dedicated protocol.

Magic wormhole still doesn't have an easy way to run on windows, i have to download a 2.4GB VC Build tools with a shitty installer from Microsoft.
There's a Magic Wormhole implementation in Go that ships windows binaries: https://github.com/psanford/wormhole-william
Once there's a verified and tested v1 then you can start talking about deprecation. It's still beta software. Do you really think you're going to convince an enterprise or anything security critical by going "deprecate your battle-tested protocols and applications for this beta tool!".

There isn't even an explanation on that page of why it was written, why it should (or could) replace OpenPGP, how to replace it ( a handy comparison table), and which use cases the tool is good for. It'd be really great if instead of pushing for change, you'd actually provide some context and explanation.

Everybody can scream for change, few can understand (much less explain) the why and how. Maybe try and join the latter.

The problem with the idea that PGP is battletested is that it lost all the battles and learned nothing from them.