
To encrypt is to make a message or a file unreadable to anyone who does not hold the key that opens it. Two families of algorithms take part:
In practice the two are combined: that is hybrid encryption, the kind PGP uses.
PGP (Pretty Good Privacy) is the original software, written by Philip Zimmermann in 1991.
OpenPGP is the set of specifications that came from it, drawn up by a working group of the IETF . Its latest version is RFC 9580, published in 2024.
LibrePGP is a variant of these specifications, which parted from them on a few points and which GnuPG in particular follows.
PGP ID is a way of using PGP, with innovations specified one by one for standardisation: a digital identity anchored in a place and an instant of origin, whose secrets are backed up on paper and live in a security key. Learn more .
PGPID and foodjis are the original software implementing PGP ID. For now they keep to the key format both specifications share (version 4), which all the software listed below understands.
The same mechanism can add a signature , which proves who wrote the message and that it was not altered.
A copied private key is a lost private key: whoever holds a copy reads your mail, for ever. In a security key the private key never comes out: the computer or phone hands it the session key to open, and gets the answer back — never the secret.
Losing one’s phone therefore costs nothing. Losing one’s key costs what a key costs, and PGP ID’s paper backup lets a new one be written. The association provides these keys to its members.
Software that encrypts with PGP through a security key:
Software that complies with the OpenPGP or LibrePGP specifications is a powerful tool for protecting communications and data, in a world ever more exposed to cyberattacks.