Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The tooling is simple and easy to use, so it's already better than most PGP implementations in my opinion, especially for integrating within other software. I remember many programs failing to validate PGP signatures in the past because the only way they managed to reliably validate+decrypt messages was to call the gpg binary and parse the output, and by injecting output in the encrypted payload you could convince them that the message was legit.

This doesn't even attempt to replace PGP in cases where you need to deal with webs of trust or signatures, though you can build your own signature scheme by encrypting twice (after reading up on your cryptography of course).

I don't really understand what you mean by "10x better". It encrypts fast and securely, based on a readable specification. I don't know what it needs to do better to cover its intended use case.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: