RE: chaos.social/@delta/1158424466…

extreme coping because of gpg.fail and @soatok's blog post lol :neobot_3c:


Don't believe those who loudly claim email can not avoid metadata! They are ignorant of our continuous works on minimizing metadata:

DONE:

- no phone number other identifying data needed
- no cleartext "Subject"
- no cleartext "To"
- randomized "Date"
- no IP addresses
- group/avatar/attachment/etc metadata only contained in encrypted message parts

Upcoming:

- servers to never see cryptographic ID metadata
- remove "threading" and auxilliary headers
- experiment with Sealed Sender


in reply to lambda crime

why do you say coping?

If in 2026 you make generic claims against the feasibility of using #email and #openpgp for secure decentralized messaging, there hardly is a way around taking a deeper look at RFC9850 and RFC9788 and the minimalist Rust-based approach chatmail.at takes. Hammering away at gpg and other crimes of how email-encryption doesnt work well ... frankly does not cut it for making a generic "it can not work" claim. See also chaos.social/@delta/1157966260…


Relax 😎! GPG is not OpenPGP!

Yesterday, vulnerabilities were published gpg.fail but they don't affect #deltachat or other #chatmail clients because

A) We never used #gnupg for anything; we use the modern #rustlang #openpgp implementation @rpgp, security audited multiple times.

B) #openpgp is fine, as modernized in #RFC9580, which already warns against several #gpgfail issues (gpg didn't implement that spec)

Please spread the word that #gpg is not #openpgp ... Thanks! #39c3


in reply to Delta Chat

@delta My blog post was about encrypting emails.

People generally use OpenPGP because they want to encrypt emails, so the topics intersect a lot, but it was about the challenges one faces when trying to use encryption with their mail client software.

If that's not what your team is doing, then the post doesn't apply to you, so there's no need to subtoot about it.

in reply to Soatok Dreamseeker

we welcome scrutiny but prefer co-ordinated security-disclosure via

github.com/rpgp/rpgp/security/… and

github.com/chatmail/core/secur…

We'd be surprised if you find a "0day" exploit against standard #deltachat users but certainly prefer you finding something than eg putin/khomeini-aligned hackers.