Re: Cipher Preferences Ignored for Kyber keys?

"Robert J. Hansen via Gnupg-users" <[email protected]> Mon, 27 Jul 2026 12:59:47 -0400
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5067852420365618403==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="------------p3rIRFMa6COo0veUWBih8OLl"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------p3rIRFMa6COo0veUWBih8OLl
Content-Type: multipart/mixed; boundary="------------N2mZvHpr0oYQpst5lgVmMTJi";
 protected-headers="v1"; hp="clear"
Message-ID: <[email protected]>
Date: Mon, 27 Jul 2026 12:59:47 -0400
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Subject: Re: Cipher Preferences Ignored for Kyber keys?
To: [email protected]
References: <c22D-bMT1NSYBbk0Ez2qcnh8Y10L_3UwrVtsy5GnrwAtL-iqjVenVrK1GDMYgz_jEtZ2L-qLEwWVMHUKeTcR5IpQWIzUKXlfwc8qOXqchAo=@proton.me>
 <[email protected]>
 <dikqhZGAcEeGNvh0zA2_U2Ik7hxdttsjWh5ozqWlwaEOPpLZrowyuQ2xFe8XFi3MmjLUqkqKxlDfrQNQ_3eNmAhDCpMyctnpIXZNM4lLn74=@proton.me>
 <[email protected]>
Content-Language: en-US
From: "Robert J. Hansen" <[email protected]>
Autocrypt: [email protected]; keydata=
 xjMEYDPZuBYJKwYBBAHaRw8BAQdA/aB6JMIYdPYT87rjGEZcDE7UG2CJUBpdEcnEixk9f5nN
 JlJvYmVydCBKLiBIYW5zZW4gPHJqaEBzaXhkZW1vbmJhZy5vcmc+wp0EExYKAEUCGwMCF4AW
 IQR9jsS4W2/t1sENPHkeepTU6H+R1QUCYeM1LwwLCg0JDAgLBwQDAQIDIgECBxUKCQgLAwIF
 FgMBAgACHgcACgkQHnqU1Oh/kdVCrAEA3h+OrJBDx7cLmqKvjVUF19OKRBlr2186iLX54XCx
 vJEA/iO/C6+9ZlyIF3uONgE5lBdOf1hwd4J5XvPFHWk9/XsKzjgEYDPZuBIKKwYBBAGXVQEF
 AQEHQED5YZemPXK7jec7G6zB0+SOZlhHNbd2xpMCYZCGI+UwAwEIB8J4BBgWCgAgFiEEfY7E
 uFtv7dbBDTx5HnqU1Oh/kdUFAmAz2bgCGwwACgkQHnqU1Oh/kdVeEwD+OybeEHFN+78dDsVl
 X2JXz46Nex+LGgDx8gRvaM8j7B0A/1hhd1FUjeTF+Zy4x/ungsY/SHQ3phZGTvhEC9hCzMEA
In-Reply-To: <[email protected]>

--------------N2mZvHpr0oYQpst5lgVmMTJi
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

> Twofish was an AES candidate which did not make it.  Camellia was
> included for pure political reasons.

For others who wonder:

IDEA was included for PGP 2.6 support. In 1993 IDEA was a pretty good
option for civilian cryptography. It hasn't really been a defensible
choice for anything since '98 or so. We still support it.

3DES was included because back in the mid-'90s during PGP 5 development
there was some concern over the IDEA algorithm being patented and PRZ
wanting an emergency last-ditch fallback.

CAST5 was included because PGP 5 used it as a default instead of the
patented IDEA. There's been no real cause for it since '99.

BLOWFISH was included because ... ? Nobody's ever explained that to me
except to vaguely say "patents". It was there in GnuPG 1.0 and PGP 7,
both dating from '99-'00, and has never really been needed.

TWOFISH came about because in '99 some PGP financial backers were really
getting nervous over how PGP 5 was dependent on patented algorithms. PRZ
was under a lot of pressure to add a patent-free modern cipher,
preferably with government backing, to PGP. The AES competition was
underway and TWOFISH was a front-runner. PRZ gambled TWOFISH would
become AES, and put it into PGP 7. Almost as soon as he did this
Rijndael was selected to become AES, but the press releases saying
TWOFISH was being introduced to PGP 7 had already been drafted.

DSA signatures and Elgamal encryption keys were added because PGP 5 was
still trying to get away from the RSA patent. PGP 5 misnamed them as
"Diffie-Hellman" because of some business deal with the company pushing
DSA/Elg as an RSA alternative, or so I heard.

Elgamal signatures were added because ... I am unaware of the case for
including these. It was widely regarded as a mistake.

RIPEMD160 was included because some people objected intensely to PGP 5
using SHA-1 as a hash algorithm, on the grounds SHA-1 was designed at NSA=
=2E

The cipher zoo is real. It's not an embarrassment, but ... it really is
a legacy of the software patents of the late '90s. Even today, thirty
years later, we're still seeing the consequences.

> not seen a demand for other national cipher algorithms in the last 20
> years (Despite that there are at least a Russian and a Chinese set of
> algorithms).

And Ukrainian. DSTU-7456.


--------------N2mZvHpr0oYQpst5lgVmMTJi--

--------------p3rIRFMa6COo0veUWBih8OLl
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature.asc"

-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQR9jsS4W2/t1sENPHkeepTU6H+R1QUCameOgwUDAAAAAAAKCRAeepTU6H+R1RLM
AP0fNgRercbRymajVQeE7h1GuHaBTig7cqiyj9k1BhOUAAEAgAPNbwImBx06wLV7kMHOYQjeWTnK
4fiyl6g1JFBUcQQ=
=Z5jV
-----END PGP SIGNATURE-----

--------------p3rIRFMa6COo0veUWBih8OLl--


--===============5067852420365618403==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users

--===============5067852420365618403==--