You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

寻求支持Encrypt-then-MAC、Blake2/Whirlpool、无风险NIST曲线的开源PGP工具

Great question—your focus on avoiding "moderate security" primitives and prioritizing privacy over speed is totally valid, especially given the concerns you raised about RFC4880-bis. Below are open-source tools that align with your requirements (Encrypt-then-MAC, Blake2/Whirlpool, no vulnerable NIST curves, no SHA-1):

1. GnuPG (Customized for Stronger Crypto)

While GnuPG is rooted in OpenPGP, you can configure it to bypass the weaker parts of the standard and use modern, secure primitives:

  • Curves: Use ed25519 (signing) or curve25519 (encryption)—these are non-NIST, well-audited curves with no known vulnerabilities.
  • Hashing: Enable Blake2b (supported in GnuPG 2.2+) for all hash-related operations (key derivation, signatures, MDC). Set this as the default in your gpg.conf:
    s2k-digest-algo blake2b512
    digest-algo blake2b512
    disable-sha1
    
  • Encrypt-then-MAC: GnuPG uses an encrypt-then-MDC (Modification Detection Code) scheme, which is a form of encrypt-then-MAC. By using Blake2b for the MDC, you avoid the "moderate security" concerns tied to older hashes like SHA-1.

2. OpenSSL (Manual Encrypt-then-MAC Workflow)

If you want full control over every primitive, OpenSSL lets you explicitly implement an encrypt-then-MAC pipeline with your preferred algorithms:

  • Curves: Supports curve25519 for ECC key exchange, so you can avoid vulnerable NIST curves.
  • Hashing/MAC: Supports both Blake2b/Blake2s and Whirlpool for HMAC operations.
  • Example Workflow:
    1. Encrypt your file with a strong cipher (e.g., AES-256-CBC):
      openssl enc -aes-256-cbc -salt -in plainfile.txt -out encrypted.enc -pass file:./secret_key
      
    2. Compute a Blake2b HMAC of the ciphertext to act as your MAC:
      openssl dgst -blake2b512 -mac hmac -macopt key:./mac_secret encrypted.enc > encrypted.enc.hmac
      
    3. To verify, recompute the HMAC and compare it to the stored value before decrypting.
  • Note: This requires manual steps, but it’s perfect if you want to avoid any implicit reliance on standards you don’t trust.

3. Schnorrkel (Post-Quantum Resistant Option)

For an extra layer of future-proofing, schnorrkel is an open-source tool focused on Curve25519-based Schnorr signatures and encryption:

  • Curves: Uses the Ristretto255 group (based on Curve25519), which is secure and avoids NIST curve pitfalls.
  • Hashing: Uses Blake2b for all hash and MAC operations.
  • Encrypt-then-MAC: Implements explicit encrypt-then-MAC with Blake2b, aligning perfectly with your requirement.
  • Note: It’s less mainstream than the other tools, but it’s a great choice if you want to prioritize cutting-edge, post-quantum-resistant crypto.

Final Recommendation

If you want a balance of ease of use and adherence to all your requirements, GnuPG with custom configuration is a solid choice. If you’d rather ditch OpenPGP entirely and want full control over every step, OpenSSL or Schnorrkel are excellent options.

内容的提问来源于stack exchange,提问作者user170196

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:55:33