logoalt Hacker News

anta40last Saturday at 6:57 AM1 replyview on HN

I'm curious. What's the advantage of using signify/minisign instead of good old PGP/GPG?


Replies

some_furrylast Saturday at 7:02 AM

PGP/GPG is a complicated mess designed in the 1990's and only incrementally updated to add more complexity and cover more use-cases, most of which you'll never need. Part of PGP/GPG is supporting a large swath of algorithms (from DSA to RSA to ECDSA to EdDSA to whatever post-quantum abomination they'll cook up next).

Signify/Minisign is Ed25519. Boring, simple, fit-for-purpose.

You can write an implementation of Minisign in most languages with little effort. I did in PHP years ago. https://github.com/soatok/minisign-php

Complexity is the enemy of security.