2026-09-01 11:33 UTC
@debacle @marsik @Goffi @nigel @andros
I have, and am still in one case using PGP over XMPP. The nice thing is the single identity that can be transferred to all the devices. You only have to verify a particular identity once and it doesn't matter if they change devices or get another device like with other schemes.
I am not really worried that a server operator is making a long term archive of my messages in a way that forward secrecy might help at some point in the future. Attackers on the network don't have access to my messages on the network due to the regular use of TLS on XMPP these days. There is no technical reason that you couldn't switch out encryption keys on PGP over XMPP for forward secrecy, since the public keys are always available on the server and can be refreshed at any time.
One subtlety that did not immediately occur to me involves the difference between instant messaging and email. You might not want to risk your email keys on something that exposes them all the time...
Replies (0)
No replies.