After decades of platform lock-in, the first truly portable social graph standard has arrived. It’s…

    • Arthur Besse@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      27 days ago

      A PGP key is neither necessary[1] nor sufficient[2] for a PGP email user to be able to use their email account, so neither the loss or leak of a PGP private key is as consequential as the loss or leak of a cryptographic capability like a nostr key is.

      On the other hand, the history and present of PGP usage does provide some good arguments for my point that responsible key custody is difficult: most PGP users keep our keys encrypted, some on HSMs; many people often don’t carry them around; and very few would advise pasting a PGP private key in to new shiny apps one might stumble across the way that people do with their nostr keys today.


      1. if you lose access to your PGP key it doesn’t mean you need to stop using that email address ↩︎

      2. if I obtain your PGP secret key, that doesn’t let me log into your IMAP server ↩︎