Re: Cipher Preferences Ignored for Kyber keys?
"Robert J. Hansen via Gnupg-users" <[email protected]> Mon, 27 Jul 2026 12:59:47 -0400
| Newsgroups | gmane.comp.encryption.gpg.user |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============5067852420365618403== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------p3rIRFMa6COo0veUWBih8OLl" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------p3rIRFMa6COo0veUWBih8OLl Content-Type: multipart/mixed; boundary="------------N2mZvHpr0oYQpst5lgVmMTJi"; protected-headers="v1"; hp="clear" Message-ID: <[email protected]> Date: Mon, 27 Jul 2026 12:59:47 -0400 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Cipher Preferences Ignored for Kyber keys? To: [email protected] References: <c22D-bMT1NSYBbk0Ez2qcnh8Y10L_3UwrVtsy5GnrwAtL-iqjVenVrK1GDMYgz_jEtZ2L-qLEwWVMHUKeTcR5IpQWIzUKXlfwc8qOXqchAo=@proton.me> <[email protected]> <dikqhZGAcEeGNvh0zA2_U2Ik7hxdttsjWh5ozqWlwaEOPpLZrowyuQ2xFe8XFi3MmjLUqkqKxlDfrQNQ_3eNmAhDCpMyctnpIXZNM4lLn74=@proton.me> <[email protected]> Content-Language: en-US From: "Robert J. Hansen" <[email protected]> Autocrypt: [email protected]; keydata= xjMEYDPZuBYJKwYBBAHaRw8BAQdA/aB6JMIYdPYT87rjGEZcDE7UG2CJUBpdEcnEixk9f5nN JlJvYmVydCBKLiBIYW5zZW4gPHJqaEBzaXhkZW1vbmJhZy5vcmc+wp0EExYKAEUCGwMCF4AW IQR9jsS4W2/t1sENPHkeepTU6H+R1QUCYeM1LwwLCg0JDAgLBwQDAQIDIgECBxUKCQgLAwIF FgMBAgACHgcACgkQHnqU1Oh/kdVCrAEA3h+OrJBDx7cLmqKvjVUF19OKRBlr2186iLX54XCx vJEA/iO/C6+9ZlyIF3uONgE5lBdOf1hwd4J5XvPFHWk9/XsKzjgEYDPZuBIKKwYBBAGXVQEF AQEHQED5YZemPXK7jec7G6zB0+SOZlhHNbd2xpMCYZCGI+UwAwEIB8J4BBgWCgAgFiEEfY7E uFtv7dbBDTx5HnqU1Oh/kdUFAmAz2bgCGwwACgkQHnqU1Oh/kdVeEwD+OybeEHFN+78dDsVl X2JXz46Nex+LGgDx8gRvaM8j7B0A/1hhd1FUjeTF+Zy4x/ungsY/SHQ3phZGTvhEC9hCzMEA In-Reply-To: <[email protected]> --------------N2mZvHpr0oYQpst5lgVmMTJi Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable > Twofish was an AES candidate which did not make it. Camellia was > included for pure political reasons. For others who wonder: IDEA was included for PGP 2.6 support. In 1993 IDEA was a pretty good option for civilian cryptography. It hasn't really been a defensible choice for anything since '98 or so. We still support it. 3DES was included because back in the mid-'90s during PGP 5 development there was some concern over the IDEA algorithm being patented and PRZ wanting an emergency last-ditch fallback. CAST5 was included because PGP 5 used it as a default instead of the patented IDEA. There's been no real cause for it since '99. BLOWFISH was included because ... ? Nobody's ever explained that to me except to vaguely say "patents". It was there in GnuPG 1.0 and PGP 7, both dating from '99-'00, and has never really been needed. TWOFISH came about because in '99 some PGP financial backers were really getting nervous over how PGP 5 was dependent on patented algorithms. PRZ was under a lot of pressure to add a patent-free modern cipher, preferably with government backing, to PGP. The AES competition was underway and TWOFISH was a front-runner. PRZ gambled TWOFISH would become AES, and put it into PGP 7. Almost as soon as he did this Rijndael was selected to become AES, but the press releases saying TWOFISH was being introduced to PGP 7 had already been drafted. DSA signatures and Elgamal encryption keys were added because PGP 5 was still trying to get away from the RSA patent. PGP 5 misnamed them as "Diffie-Hellman" because of some business deal with the company pushing DSA/Elg as an RSA alternative, or so I heard. Elgamal signatures were added because ... I am unaware of the case for including these. It was widely regarded as a mistake. RIPEMD160 was included because some people objected intensely to PGP 5 using SHA-1 as a hash algorithm, on the grounds SHA-1 was designed at NSA= =2E The cipher zoo is real. It's not an embarrassment, but ... it really is a legacy of the software patents of the late '90s. Even today, thirty years later, we're still seeing the consequences. > not seen a demand for other national cipher algorithms in the last 20 > years (Despite that there are at least a Russian and a Chinese set of > algorithms). And Ukrainian. DSTU-7456. --------------N2mZvHpr0oYQpst5lgVmMTJi-- --------------p3rIRFMa6COo0veUWBih8OLl Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc" -----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQR9jsS4W2/t1sENPHkeepTU6H+R1QUCameOgwUDAAAAAAAKCRAeepTU6H+R1RLM AP0fNgRercbRymajVQeE7h1GuHaBTig7cqiyj9k1BhOUAAEAgAPNbwImBx06wLV7kMHOYQjeWTnK 4fiyl6g1JFBUcQQ= =Z5jV -----END PGP SIGNATURE----- --------------p3rIRFMa6COo0veUWBih8OLl-- --===============5067852420365618403== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Gnupg-users mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-users --===============5067852420365618403==--