Quoting myself in a mood today at work
```#GPG keys have two parts: the private key (which is fiercely protected) and the public key (which is handed out like sleazy leaflets on a Las Vegas street corner.)```
Quoting myself in a mood today at work
```#GPG keys have two parts: the private key (which is fiercely protected) and the public key (which is handed out like sleazy leaflets on a Las Vegas street corner.)```
Made a few updates and released a new version of #calliope , a #bash script based utility to write a journal using #LaTeX. Since it's #LaTeX based, you can pretty much add whatever you wish to your journal---images, other PDFs, beautiful maths, and of course, you can customise it as you wish to suit your needs. It's all managed by #Git and if you'd like you can encrypt your journal entries using #gpg
Check it out on #GitHub : https://github.com/sanjayankur31/calliope
Non, #Google ne proposera pas un vrai #chiffrement de bout en bout sur #Gmail. Le mécanisme proposé n'est pas considéré comme un véritable chiffrement "E2EE" par certains experts. En effet, il implique un serveur de gestion de clés interne à l'entreprise.
https://www.clubic.com/actualite-560031-non-google-ne-proposera-pas-un-vrai-chiffrement-de-bout-en-bout-sur-gmail.html
Mieux vaut utiliser soit #protonmail soit #thunderbird avec #gpg et une adresse mail chez un hébergeur non #gafam respectant les #donneespersonnelles
For years now I’ve had a bit of a bee under my cap: would it be possible to unlock a Vault file with a GnuPG-compatible smart card? And what if the smart card were local and the unlocking had to be triggered remotely?
Forwarding GnuPG agent over SSH
https://jpmens.net/2025/04/04/forwarding-gnupg-agent-over-ssh/
@Xeniax Totally nerdsniped :D I'd love to be a part of the study.
I don't think that #KeyServers are dead. I think they evolved into Verifying Key Servers (VKS), like the one run by a few folks from the OpenPGP ecosystem at https://keys.openpgp.org/about . More generally, I believe that #PGP / #GPG / #OpenPGP retains important use-cases where accountability is prioritized, as contrasted with ecosystems (like #Matrix, #SignalMessenger) where deniability (and Perfect Forward Secrecy generally) is prioritized. Further, PGP can still serve to bootstrap those other ecosystems by way of signature notations (see the #KeyOxide project).
Ultimately, the needs of asynchronous and synchronous cryptographic systems are, at certain design points, mutually exclusive (in my amateur estimation, anyway). I don't think that implies that email encryption is somehow a dead-end or pointless. Email merely, by virtue of being an asynchronous protocol, cannot meaningfully offer PFS (or can it? Some smart people over at crypto.stackexchange.com seem to think there might be papers floating around that can get at it: https://crypto.stackexchange.com/questions/9268/is-asynchronous-perfect-forward-secrecy-possible).
To me, the killer feature of PGP is actually not encryption per se. It's certification, signatures, and authentication/authorization. I'm more concerned with "so-and-so definitely said/attested to this" than "i need to keep what so-and-so said strictly private/confidential forever and ever." What smaller countries like Croatia have done with #PKI leaves me green with envy.
Duuz puääng eli täydet pisteet muuten saksalaisen #Filen-#pilvi-palvelun #asiakaspalvelu'lle. Valitin heille aamupäivällä, että vaikka he tarjoavat #Linux-työpöytäintegraatiota, #RPM-asennuspakettia ei ole #GPG-allekirjoitettu eli se ei ns. voimatoimitta asennu #openSUSE'en tai #Fedora'an. Jo iltapäivästä tuli vastaus: tiedossa on, ja korjataan ensi tilassa. #BoycottUSA #atkjuttuja
“Unless you are using #GPG, email is not end-to-end encrypted, & the contents of a message can be intercepted & read at many points, including on Google’s email servers,” said Eva Galperin, director of #cybersecurity at the Electronic Frontier Foundation.
#NationalSecurity experts have expressed alarm over the #Trump admin’s denial that the leaked #Signal chat contained #classified information.
#porkbun has #email with @protonprivacy, really affordably. So I switched my business mail to that, and I have it all setup in #emacs! :D @daviwil is a goddamned treasure. I would not be able to setup my workflow this well without Systems Crafters! I'm happy! I feel so #secure and #cozy, and I can do #gpg for a little extra. Just don't let crazy Christians on my e-mail chains. I don't want to pull a Hegseth.
finally found some time to play with #SOPS (https://getsops.io/docs/) and migrated a project to it. seems like a good replacement and optimization for our current secrets sharing workflow. also super useful that it works with both #PGP/ #GPG and #age keys
07.03.2025: GnuPG announces release of 2.5.5 for public testing, finalized PQC algorithms are supported.
Source: https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html
11.03.2025: NIST selects HQC as fifth algorithm for post-quantum encryption.
Source: https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption
PQC: https://wikipedia.org/wiki/Post-quantum_cryptography
GnuPG: https://mastodon.online/@blueghost/111974048270035570
Harvest now, decrypt later: https://mastodon.online/@blueghost/111357939714657018
admin email public key #GPG
-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEZ9LrwxYJKwYBBAHaRw8BAQdAR0WzceV3yBHwzyj0bgA4HxO5GXFjawU0+pfC
bbT2fD60L0J5emFudGluZSBOZXh1cyBBZG1pbiA8YWRtaW5AYnl6YW50aW5lbmV4
dXMuaW8+iJkEExYKAEEWIQTgTgBQhrPwCwUm6F+1hI+KU0bXdAUCZ9LrwwIbAwUJ
BaUBPQULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRC1hI+KU0bXdIneAP0c
o0oLZOm61kn/CTdB2Yzq70oJbY8MGSBiBS2UiAwQ9QEA5L68kYOr+C2m9pxUhzCa
So+MO3NTBhai2hfDyrw2LQq4OARn0uvDEgorBgEEAZdVAQUBAQdAn0f8K1jCFlXj
G7q1dJ1gmjJbslyxROW5epwul+lUOx8DAQgHiH4EGBYKACYWIQTgTgBQhrPwCwUm
6F+1hI+KU0bXdAUCZ9LrwwIbDAUJBaUBPQAKCRC1hI+KU0bXdMwIAP94/es2lb+1
6SXryet+HOmpY+U41/v9o8aLF7KAhCIA6QD/cGDfdFBBg1mEWEZdI+7tCEieaAgS
0qrnFZJeDgt/7AA=
=y1x/
-----END PGP PUBLIC KEY BLOCK-----
The gender pay gap at the top: the role of networks https://d.repec.org/n?u=RePEc:ptu:wpaper:w202423&r=&r=soc
"…female top managers in Portugal earn 25% less than their male counterparts, even after controlling for factors such as age, education, and tenure.
… introducing new metrics for #network size and gender composition based on managers’ past interactions, … networks account for 20% of this pay gap, primarily through firm #sorting, as networks enable access to higher-paying firms. Focusing on episodes of transitions between firms, we estimate a pay gap of around 22%, indicating that most of the gender pay gap originates during the #hiring process.… one-third of the gap is explained by differences in networks. The #networkEffect works through two channels: by facilitating access to higher-paying firms (70% of the effect) and by enhancing #bargainingPower during salary negotiations in the new firm (30%).
#wages #gpg #LaborMarkets
I recently realized that Git commits could be made on your behalf without your consent.
This could happen because either you left your computer unlocked in a public place (or any place actually), your computer got stolen and the disk wasn't encrypted or any of those combinations.
To prevent this, Git has a "signing" mechanism that proves without any doubt that you made that commit.
It uses GPG, and with power of cryptography, it protects your work from being hacked.
Has anyone here on #fedi figured out the correct recipe for dealing with #OpenPGP, #DMARC and #mailman ?
The problem, by default mailman will modify messages and this will break the dkim signature.
https://gitlab.com/mailman/mailman/-/issues/1079
Mailman provides two DMARC mitigation options (other option is reject or discard which is not useful in this case).
1. Replace the from address with list address
2. Wrap original message in an envelope
thunderbird flags 1 and fails 2.
#askfedi #gnupg #gpg #thunderbird
@lns sorry, but no. gnupgp UX sucks so hard that even I don't get it without extensive internet searching.
And I heard horrible stuff about integration into programs, like that they need to kill the #gpg daemon regularly to make it work.
Let's rather invest our efforts into making modern alternatives like #rpgp and #rsop
https://crates.io/crates/rsop/ great.
Does the Gender Wage Gap Actually Reflect Taste Discrimination Against Women? https://d.repec.org/n?u=RePEc:nbr:nberwo:33405&r=&r=lab
"… misogyny is an economically meaningful and statistically significant predictor of the wage gap
… test more explicit implications of taste discrimination. The data are inconsistent with the Becker taste discrimination model
But the data are consistent with the effects of taste discrimination against women in search models, in which #discrimination on the part of even a small group of misogynists can result in a wage gap."
#gpg #wages
Everybody should learn how to use GPG.
Hallo #unplugtrump, ich suche unter #ios und #ipados ein #mail program am besten #opensource mit Möglichkeit #gpg / #pgp zu verwenden.
Danke
I made a guide, it's clumsy and sloppy but it's something.
This is for setting up GPG on Android for people who need secure communication that can't be shut down and doesn't rely on government services, especially trackable services.
foggyminds.com/extra/OpenKeyCh…
Tagging trans community because I think we need these networks for when things get worse.