{"id":112077,"date":"2023-12-08T15:10:14","date_gmt":"2023-12-08T13:10:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/avtor-gnupg-osnoval-librepgp-fork-standarta-openpgp"},"modified":"2023-12-08T15:10:14","modified_gmt":"2023-12-08T13:10:14","slug":"avtor-gnupg-osnoval-librepgp-fork-standarta-openpgp","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/avtor-gnupg-osnoval-librepgp-fork-standarta-openpgp","title":{"rendered":"The author of GnuPG founded LibrePGP, a fork of the OpenPGP standard.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Werner Koch, the main developer and creator of the GnuPG (GNU Privacy Guard) project, established the LibrePGP project, focused on developing an updated specification alternative to the OpenPGP standard. The fork was created in response to changes proposed by the IETF working group for the next specification update of OpenPGP (RFC-4880), which Koch perceived as questionable in terms of maintaining compatibility and ensuring security. Supporters of the fork, including developers from GnuPG, RNP (the OpenPGP implementation from Thunderbird), and Gpg4win, fear that the proposed changes could be detrimental to existing OpenPGP-based application implementations, whose users rely on the long-term stability of the specification and are not willing to accept changes that disrupt compatibility.    <\/p>\n<p>LibrePGP includes useful improvements developed in recent years for the future version of the OpenPGP specification, while excluding changes that negatively impact compatibility. For example, compared to the current standard RFC-4880, LibrePGP includes features such as:  <\/p>\n<ul>\n<li class=\"l\"> Support for the Camellia encryption algorithm (RFC-5581),\n<li class=\"l\"> ECC (Elliptic Curve Cryptography) extensions for OpenPGP (RFC-6637).\n<li class=\"l\"> Mandatory support for SHA2-256 hashes (SHA-1 and MD5 are considered deprecated, and the ability to decrypt data without verifying integrity is classified as completely outdated).\n<li class=\"l\"> Increased fingerprint size to 256 bits.\n<li class=\"l\"> Support for digital signature schemes EdDSA and elliptic curves BrainpoolP256r1, BrainpoolP384r1, BrainpoolP512r1, Ed25519, Curve25519, Ed488, and X448.\n<li class=\"l\"> Support for the CRYSTALS-Kyber algorithm, resistant to attacks from quantum computers.\n<li class=\"l\"> Support for authenticated encryption modes OCB (Offset Codebook Mode).\n<li class=\"l\"> Implementation of the fifth version of the digital signature format with metadata protection.\n<li class=\"l\"> Support for extended subpackets with digital signatures.  <\/ul>\n<p>Key elements of criticism of the new OpenPGP specification:  <\/p>\n<ul>\n<li class=\"l\"> The IETF working group has attempted to reinvent the standard instead of a gradual incremental update to the specification, introducing significant changes that disrupt compatibility.\n<li class=\"l\"> The imposition of support for the GCM (Galois\/Counter Mode) symmetric encryption mode, which is difficult to implement correctly, while ignoring the OCB (Offset Codebook Mode), for which patents expired several years ago.\n<li class=\"l\"> The addition of optional packets with random padding to protect against traffic analysis. According to the creators of LibrePGP, such packets with unverifiable initial random padding pose a threat of being used to create hidden data transmission channels and bypass data leakage prevention systems. Previously, the idea of including padding was rejected as being an issue at the application layer rather than the encryption layer.\n<li class=\"l\"> The use of a modified ECDH encryption scheme (changing the OID format), instead of the version already described in RFC-6637 and implemented in PGP and GnuPG.\n<li class=\"l\"> Removal of some commonly used features, such as the classic key revocation method, the flag &#171;m&#187; for marking MIME data, and the flag &#171;t&#187; for separating text data from binary data (the flag &#171;t&#187; has been replaced by the flag &#171;u&#187; for UTF-8 text).\n<li class=\"l\"> The refusal to include metadata protection of the signed file in the new signature format (for example, without violating the signatures, one can change the file name).\n<li class=\"l\"> The dubious ability to add 'salt' to signatures (Salted Signature) to enhance protection against prefix collision attacks. The salted value can be used as an undetectable hidden channel to transmit 32 bytes of data in the signature.\n<li class=\"l\"> A shift of the standard towards the primary use for online communication, ignoring the needs for long-term data storage.  <\/ul>\n<p>Supporters of OpenPGP have already published criticisms of the criticism. In the end, if a compromise cannot be found, the split may lead to increasing incompatibilities in OpenPGP\/LibrePGP implementations. Partially to address this issue, OpenPGP developers have fixed the fifth version of the signature format in a manner compatible with LibrePGP and have started working on the sixth version.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60256\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u0435\u0440\u043d\u0435\u0440 \u041a\u043e\u0445 (Werner Koch), \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u0438 \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GnuPG (GNU Privacy Guard), \u043e\u0441\u043d\u043e\u0432\u0430\u043b \u043f\u0440\u043e\u0435\u043a\u0442 LibrePGP, \u0441\u043e\u0441\u0440\u0435\u0434\u043e\u0442\u043e\u0447\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u0440\u0430\u0437\u0432\u0438\u0442\u0438\u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0443 OpenPGP. \u0424\u043e\u0440\u043a \u0431\u044b\u043b \u0441\u043e\u0437\u0434\u0430\u043d \u0432 \u043e\u0442\u0432\u0435\u0442 \u043d\u0430 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043d\u0430\u043c\u0435\u0447\u0435\u043d\u043d\u044b\u0435 \u0440\u0430\u0431\u043e\u0447\u0435\u0439 \u0433\u0440\u0443\u043f\u043f\u043e\u0439 IETF \u0434\u043b\u044f \u0432\u043d\u0435\u0441\u0435\u043d\u0438\u044f \u0432 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 OpenPGP (RFC-4880) \u0438 \u0432\u043e\u0441\u043f\u0440\u0438\u043d\u044f\u0442\u044b\u0435 \u041a\u043e\u0445\u043e\u043c \u043a\u0430\u043a \u0441\u043e\u043c\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u0441 \u0442\u043e\u0447\u043a\u0438 \u0437\u0440\u0435\u043d\u0438\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-112077","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u0435\u0440\u043d\u0435\u0440 \u041a\u043e\u0445 (Werner Koch), \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u0438 \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GnuPG (GNU Privacy Guard), \u043e\u0441\u043d\u043e\u0432\u0430\u043b \u043f\u0440\u043e\u0435\u043a\u0442 LibrePGP, \u0441\u043e\u0441\u0440\u0435\u0434\u043e\u0442\u043e\u0447\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u0440\u0430\u0437\u0432\u0438\u0442\u0438\u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0443 OpenPGP.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/avtor-gnupg-osnoval-librepgp-fork-standarta-openpgp\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0432\u0442\u043e\u0440 GnuPG \u043e\u0441\u043d\u043e\u0432\u0430\u043b LibrePGP, \u0444\u043e\u0440\u043a \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0430 OpenPGP | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u0435\u0440\u043d\u0435\u0440 \u041a\u043e\u0445 (Werner Koch), \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u0438 \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GnuPG (GNU Privacy Guard), \u043e\u0441\u043d\u043e\u0432\u0430\u043b \u043f\u0440\u043e\u0435\u043a\u0442 LibrePGP, \u0441\u043e\u0441\u0440\u0435\u0434\u043e\u0442\u043e\u0447\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u0440\u0430\u0437\u0432\u0438\u0442\u0438\u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0443 OpenPGP.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/avtor-gnupg-osnoval-librepgp-fork-standarta-openpgp\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-12-08T13:10:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-12-08T13:10:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47The author of GnuPG founded LibrePGP, a fork of the OpenPGP standard | ProHoster","description":"Werner Koch, the main developer and creator of the GnuPG (GNU Privacy Guard) project, founded the LibrePGP project focused on the development of an updated specification, an alternative to the OpenPGP standard.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/avtor-gnupg-osnoval-librepgp-fork-standarta-openpgp","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0432\u0442\u043e\u0440 GnuPG \u043e\u0441\u043d\u043e\u0432\u0430\u043b LibrePGP, \u0444\u043e\u0440\u043a \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0430 OpenPGP | ProHoster","og:description":"\u0412\u0435\u0440\u043d\u0435\u0440 \u041a\u043e\u0445 (Werner Koch), \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a \u0438 \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u044c \u043f\u0440\u043e\u0435\u043a\u0442\u0430 GnuPG (GNU Privacy Guard), \u043e\u0441\u043d\u043e\u0432\u0430\u043b \u043f\u0440\u043e\u0435\u043a\u0442 LibrePGP, \u0441\u043e\u0441\u0440\u0435\u0434\u043e\u0442\u043e\u0447\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u0440\u0430\u0437\u0432\u0438\u0442\u0438\u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0443 OpenPGP.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/avtor-gnupg-osnoval-librepgp-fork-standarta-openpgp","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-12-08T13:10:14+00:00","article:modified_time":"2023-12-08T13:10:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/112077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=112077"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/112077\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=112077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=112077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=112077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}