this post was submitted on 22 Sep 2026
65 points (100.0% liked)

Open Source

49226 readers
236 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 7 years ago
MODERATORS
top 7 comments
sorted by: hot top controversial new old
[–] doubtingtammy@lemmy.ml 2 points 5 days ago

The collar/padlock is such a good look for a cryptography talk

[–] ikogarane@lemmy.world 17 points 1 week ago (3 children)

GnuPG is one of those tools I never got around to use. How could something designed for human communication be so utterly cumbersome and confusing ?

[–] modem_down@thebrainbin.org 1 points 4 days ago

How could something designed for human communication be so utterly cumbersome and confusing ?

Several reasons, I guess?

1. The PGP (later, OpenPGP) protocol.

The proprietary PGP software, which was the initial implementation of the PGP protocol(s) also suffered from usability problems:

2. GnuPG maintainers are implicitly using asymptotic software versioning

Donald Knuth was probably the most notable proponent of the idea that software packages should increasingly tend toward stability, with fewer and fewer patches needed. He used explicitly asymptotic version numbering for TeX and Metafont.

Some of the quotes in OP's video make imply GnuPG's maintainers are implicitly following a similar approach, e.g. the section about "Sequoia's need for churn".

With encryption software, there is an especially strong argument for being conservative about changes. Patches may have unforeseen consequences, adding subtle vulnerabilities.

However, the downside of this, as the gpg.fail team pointed out, is that it biases the GnuPG maintainers towards excessive rejection of patches. Especially patches that would improve usability. Arguably, TeX suffered from a similar bias; hence the development of LaTeX and newer TeX front-ends to improve usability.

3. Changing the interface would be effortful

Improving GnuPG's interface would require quite a lot of work in itself, both to the codebase and the documentation.

Releasing a version with those changes would also require fielding a lot of support queries for many years, because decades of software manuals all over the web were written for the traditional GnuPG interface, and aren't going to be updated overnight. Some of those manuals will surely never get updated, because they are no longer maintained even though they are still online and still used.

I can sympathise with the GnuPG maintainers for finding this daunting. But the improvements are needed. Thankfully, developers of tools like minisign, age, and sequoia are taking on much of this work; it's just a pity that the work had to be done in this fragmented way through third-party efforts, instead of in GnuPG itself.

[–] diaphragmwp@discuss.tchncs.de 2 points 6 days ago

If you ignore most of it, it's actually fine.

[–] HelloRoot@lemy.lol 3 points 1 week ago

Very interesting talk, thanks for sharing!