寻求支持Encrypt-then-MAC、Blake2/Whirlpool、无风险NIST曲线的开源PGP工具
Great question—your focus on avoiding "moderate security" primitives and prioritizing privacy over speed is totally valid, especially given the concerns you raised about RFC4880-bis. Below are open-source tools that align with your requirements (Encrypt-then-MAC, Blake2/Whirlpool, no vulnerable NIST curves, no SHA-1):
1. GnuPG (Customized for Stronger Crypto)
While GnuPG is rooted in OpenPGP, you can configure it to bypass the weaker parts of the standard and use modern, secure primitives:
- Curves: Use
ed25519(signing) orcurve25519(encryption)—these are non-NIST, well-audited curves with no known vulnerabilities. - Hashing: Enable Blake2b (supported in GnuPG 2.2+) for all hash-related operations (key derivation, signatures, MDC). Set this as the default in your
gpg.conf:s2k-digest-algo blake2b512 digest-algo blake2b512 disable-sha1 - Encrypt-then-MAC: GnuPG uses an encrypt-then-MDC (Modification Detection Code) scheme, which is a form of encrypt-then-MAC. By using Blake2b for the MDC, you avoid the "moderate security" concerns tied to older hashes like SHA-1.
2. OpenSSL (Manual Encrypt-then-MAC Workflow)
If you want full control over every primitive, OpenSSL lets you explicitly implement an encrypt-then-MAC pipeline with your preferred algorithms:
- Curves: Supports
curve25519for ECC key exchange, so you can avoid vulnerable NIST curves. - Hashing/MAC: Supports both Blake2b/Blake2s and Whirlpool for HMAC operations.
- Example Workflow:
- Encrypt your file with a strong cipher (e.g., AES-256-CBC):
openssl enc -aes-256-cbc -salt -in plainfile.txt -out encrypted.enc -pass file:./secret_key - Compute a Blake2b HMAC of the ciphertext to act as your MAC:
openssl dgst -blake2b512 -mac hmac -macopt key:./mac_secret encrypted.enc > encrypted.enc.hmac - To verify, recompute the HMAC and compare it to the stored value before decrypting.
- Encrypt your file with a strong cipher (e.g., AES-256-CBC):
- Note: This requires manual steps, but it’s perfect if you want to avoid any implicit reliance on standards you don’t trust.
3. Schnorrkel (Post-Quantum Resistant Option)
For an extra layer of future-proofing, schnorrkel is an open-source tool focused on Curve25519-based Schnorr signatures and encryption:
- Curves: Uses the Ristretto255 group (based on Curve25519), which is secure and avoids NIST curve pitfalls.
- Hashing: Uses Blake2b for all hash and MAC operations.
- Encrypt-then-MAC: Implements explicit encrypt-then-MAC with Blake2b, aligning perfectly with your requirement.
- Note: It’s less mainstream than the other tools, but it’s a great choice if you want to prioritize cutting-edge, post-quantum-resistant crypto.
Final Recommendation
If you want a balance of ease of use and adherence to all your requirements, GnuPG with custom configuration is a solid choice. If you’d rather ditch OpenPGP entirely and want full control over every step, OpenSSL or Schnorrkel are excellent options.
内容的提问来源于stack exchange,提问作者user170196

