[messaging] alternative to OpenPGP?

Simon Josefsson simon at josefsson.org
Fri Aug 14 03:07:04 PDT 2015


Mansour Moufid <mansourmoufid at gmail.com> writes:

> Hi everyone,
>
> Is there an alternative to the OpenPGP message format?
>
> There are three problems with OpenPGP, that I understand: metadata; [1]
> format oracles; [2] and difficulty of implementation. [3]
>
> There are many more problems[4] but I care about these three.
>
> So I'm looking for an alternative message format which: has minimal
> metadata; requires authenticated encryption; and is trivial to parse
> with Hammer.
>
> Does one exist?

Have you looked at JSON Web Encryption?

https://tools.ietf.org/html/rfc7516

For completeness, this discussion should mention S/MIME.  I cannot
recall any technical advantage it has over OpenPGP though, so if OpenPGP
is not sufficient for you, S/MIME likely aren't either.

/Simon
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 472 bytes
Desc: not available
URL: <http://moderncrypto.org/mail-archive/messaging/attachments/20150814/7083c07a/attachment.sig>


More information about the Messaging mailing list