Hereby I am announcing the (obvious) permanent hiatus of the NeoPG project. I could not complete a modern replacement for GnuPG, but I learned a lot on the way and found a new place in the scientific community, where I could apply and extend my knowledge even more!
I appreciate the interest that people had in the project, and the contributions made to it. Of course, the code remains up for anybody who is interested. Unfortunately, I lost the domain to a domain grabber, but I will try to get the content of the site online somewhere.
Hereby I am announcing the (obvious) permanent hiatus of the NeoPG project. I could not complete a modern replacement for GnuPG, but I learned a lot on the way and found a new place in the scientific community, where I could apply and extend my knowledge even more!
As this is a paid, full-time position, I have no needs for the donations collected through Patreon, and not enough time to continue NeoPG developemnt. Thus, I have donating all money that was given to me for NeoPG development to UNICEF USA: $183.61 collected over two years.
@ju916@seecurity That seems to be half of it, the other half being missing signatures for external users (Outlook) and reuse of SRP password for secret key storage.
@domschuermann Basically, it needs to be carved down to what messengers support. Expect some resistance from marketing platforms like mailchimp, although they support mobile, too, so why not?
https://t.co/B6X3ZMrMxV launched Operation JASK during the weekend to tackle security flaws such as SigSpoof in linux and open source software:
https://t.co/pjcygV5O68 https://t.co/pjcygV5O68
@marcan42 Please read the last 3 parapgraphs in @matthew_d_green summary of what's wrong with #OpenPGP. GnuPG's announcement did nothing to help understanding in the community, that's why I actually went through the clients and reported issues. #leadership#sigspoof https://t.co/DpwjUEmXHH
Someone asked me to summarize my views on the Efail matter, and the “controversy” in the PGP community. In case my rants yesterday were too incoherent for you, this is how I responded. https://t.co/D5L2Txm8PH
That's it, folks! After 2 weeks I am now too terrified to look at any more source code of software using #gnupg. Please, help finding+fixing these bugs! And now: SigSpoof 3: Breaking signature verification in #pass (password store) CVE-2018-12356 https://t.co/2iDSxno5gn #openpgp
@jlwallen@olddellian It's an uphill battle, and OpenPGP is many things to many people, leading to frustrating ambivalences. What's your primary use case? Email?
This is terrible adivce, @jlwallen. Don't put photos in gpg keys, don't look at photos in keys, don't trust keys based on photos and don't teach people to do that. Just don't do anything photo with gpg. #omg https://t.co/5IVpL30QnY
@olddellian@jlwallen Clearly, that's what WhatsApp and Signal do, but once you click on it you get the whole conversation history, thus context and additional confirmation. It's not an isolated feature, but thoughtfully integrated into specific workflows.