EMZETT.
Login

GPG

In short: “GNU Privacy Guard” — a free implementation of the OpenPGP standard for encrypting, decrypting and digitally signing files and emails.

In more detail: GPG uses asymmetric encryption: every user has a key pair made up of a public and a private key. Encrypted messages to a person are encrypted with their public key and can only be read with the corresponding private key. GPG is often used for signed Git commits, encrypted emails and signing software releases. Graphical interfaces such as Kleopatra make key management more accessible than the pure command line.

In Depth

Typical GPG command-line commands for everyday use:

# Generate a new key pair
gpg --full-generate-key
 
# Export your public key to share it
gpg --export --armor your@email.com > public-key.asc
 
# Encrypt a file with the recipient's public key
gpg --encrypt --recipient recipient@email.com file.txt
 
# Decrypt an encrypted file with your own private key
gpg --decrypt file.txt.gpg
 
# Sign a Git commit with your own key
git commit -S -m "Commit message"

A central concept in GPG is the “web of trust”: instead of a central certificate authority (as with TLS certificates), users verify each other by signing the public key of a person whose identity they’ve checked personally (e.g. at a “key-signing party”). The more trustworthy signatures a key collects, the more third parties trust it too — a decentralised counterpart to the web’s hierarchical certificate structure.

GPG keys also have a “fingerprint” — a unique hash value of the public key, through which its authenticity can be verified via a second, independent channel (e.g. read out aloud or printed on a business card) before trusting the key.

History and motivation

GPG was created in 1999 as a free, open-source alternative to PGP (“Pretty Good Privacy”, developed by Phil Zimmermann in 1991), which was at times proprietary and even subject to export restrictions in the USA (strong cryptography was long considered “munitions” under US export control laws). GPG implements the same open OpenPGP standard (RFC 4880) and is fully interoperable with other OpenPGP programs — a message encrypted with GPG can also be decrypted with any other compliant PGP implementation.

Web of trust vs. the hierarchical certificate model

The fundamental conceptual difference from TLS certificates lies in the trust model: TLS relies on a small number of central, hierarchically organised certificate authorities that browsers trust by default. GPG’s “web of trust” is completely decentralised — there’s no central authority; instead every user decides for themselves whom they trust, and this trust can be passed on transitively (I trust person A, A trusts person B, so I trust B with somewhat less certainty). This makes the system more censorship-resistant and more independent of individual institutions, but also less user-friendly — most everyday users never build a real web of trust and instead rely on directly exchanged, manually verified fingerprints.

Practical areas of use

Besides encrypted emails (used comparatively rarely in practice today, because metadata such as subject and recipient remain visible anyway and usability is low), GPG has become established above all in software development: Linux distributions sign their software packages with GPG so that package managers (e.g. apt, pacman) can check before installation that a package really comes from the stated maintainer and wasn’t manipulated in transit. Git supports signed commits and tags (git commit -S), which GitHub/GitLab mark with a “Verified” badge — protection against attackers trying to pose as another developer in a commit history.

Key revocation

An important, often overlooked GPG concept is the revocation certificate: when creating a key pair, you should already generate a revocation certificate and keep it safe (separately from the actual private key) — if you later lose access to the private key (lost passphrase, stolen device) or it’s compromised, you can use it to mark the public key as “revoked” without still needing the private key. Without a prepared revocation certificate, there’s no clean way left to warn others about a compromised key.

See also: Kleopatra, Asymmetric encryption