Heiko on Nostr: Regular PSA reminder: While GnuPG 2.5.x implements hybrid PQC encryption based on ...
Regular PSA reminder:
While GnuPG 2.5.x implements hybrid PQC encryption based on ML-KEM, just like
https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/, GnuPG's implementation is entirely incompatible with the IETF-specified format, which all other libraries are implementing.
Both serialization and the KEM combiners differ.
The bottom line is that anyone who wants to use vendor-agnostic PQC with OpenPGP should *avoid GnuPG's PQC key formats*.
This is all exceedingly unfortunate and weird, and frankly, a total disgrace.
Published at
2026-04-24 12:13:13 UTCEvent JSON
{
"id": "f25002c04de7c7eff77793341978f7b864ce27519fe3f884bb600f4bc607fdb6",
"pubkey": "e21336b31586d51a703fd8837be98cf3392456b13b362b099511a15bb15feca2",
"created_at": 1777032793,
"kind": 1,
"tags": [
[
"proxy",
"https://floss.social/@hko/116459621169318785",
"web"
],
[
"proxy",
"https://floss.social/users/hko/statuses/116459621169318785",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://floss.social/users/hko/statuses/116459621169318785",
"pink.momostr"
],
[
"-"
]
],
"content": "Regular PSA reminder:\n\nWhile GnuPG 2.5.x implements hybrid PQC encryption based on ML-KEM, just like https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/, GnuPG's implementation is entirely incompatible with the IETF-specified format, which all other libraries are implementing.\nBoth serialization and the KEM combiners differ.\n\nThe bottom line is that anyone who wants to use vendor-agnostic PQC with OpenPGP should *avoid GnuPG's PQC key formats*.\n\nThis is all exceedingly unfortunate and weird, and frankly, a total disgrace.",
"sig": "8859c6f9c493d5187dd8d2fe683c583f45d8a6adff9ec0753daea9698c525ff4cc78c4fea201a6851ca110995875891b128d91176564c7f4f6e33e427ce90248"
}