Join Nostr
2026-04-24 12:13:13 UTC

Heiko on Nostr: Regular PSA reminder: While GnuPG 2.5.x implements hybrid PQC encryption based on ...

Regular PSA reminder:

While GnuPG 2.5.x implements hybrid PQC encryption based on ML-KEM, just like https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/, GnuPG's implementation is entirely incompatible with the IETF-specified format, which all other libraries are implementing.
Both serialization and the KEM combiners differ.

The bottom line is that anyone who wants to use vendor-agnostic PQC with OpenPGP should *avoid GnuPG's PQC key formats*.

This is all exceedingly unfortunate and weird, and frankly, a total disgrace.