Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Instead of developing opinionated software with a simple interface, GPG was written to be as powerful and flexible as possible.

Moxie is the project lead for Signal, an encrypted messenger (https://signal.org/). That is what he ultimately offered.



Which is myopically focussing on encryption, not identity, signing or authentication. You send your messages in signal to someone, with no means to properly verify whom you are sending to (except if you do a nonsensical secret (because signal doesn't tell you to do it) dance of "send non-secret hello, meet in person, verify fingerprints (which people are supposedly unable to understand), send the secret stuff") or who you are receiving from. Have fun sending all your messages c/o your friendly secret service manipulating the phone number exchange.

There are things signal does better than GPG, and there are things it doesn't do at all. Which nobody tells you about until you are bitten by the resulting problems.


Look, I don't want to criticize signal, which I believe is a very nice tool, and kudos to moxie for putting this together:

however nice it may be, signal does not solve any of my problems, whereas gpg, which I agree with him, is an absolute dumpster fire, does (modulo great exertion).




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: