Training Example: GnuPG (The GNU Privacy Guard) – Review the Data, Give Your Score & Compare to the Real AI Evaluation

Industry Context — Common BS Fingerprints in Security, Surveillance & Cybersecurity
Generic Claims: protecting your business, stay ahead of threats, world-class security, trusted by enterprises…
Red Flags: guaranteed prevention of all breaches, penetration testing without accreditation, security certifications for team without named individuals, no own-practice security certifications…
Semantic Drift Patterns: homepage claims enterprise SOC but services are basic antivirus resale, claims penetration testing expertise but no CREST or CHECK accreditation, homepage targets critical infrastructure but client list is SMB, claims 24/7 SOC but no staffing or operations evidence…
Proof Expectations: CREST, CHECK, or equivalent accreditation numbers, named team with security certifications (OSCP, CISSP, CEH), ISO 27001 certification for own operations, specific case studies with anonymized but detailed findings…

GnuPG (The GNU Privacy Guard)

(https://gnupg.org) 📸 Data Snapshot: May 26, 2026

Analyze the raw signals below. How would a machine score this business’s credibility?

Here are the exact signals captured from up to six pages of the site — the same raw inputs the evaluation engine analyzed. They are grouped by signal type so you can weigh each the way the machine does.

🏗️ Semantic Structure — heading hierarchy & page identity (Info Density · Commodity Fingerprint)
HOMEPAGE The GNU Privacy Guard (https://gnupg.org)
Title

The GNU Privacy Guard

H2 The GNU Privacy Guard
H2 Reconquer your privacy
H2 News
H3 GnuPG 2.5.20 released (2026-05-13)
H3 GnuPG 2.5.19 released (2026-04-24)
H3 Security advisory T8211 for Libgcrypt (2026-04-21)   important
H3 Libgcrypt 1.12 is the new stable branch (2026-01-29)
H3 Security advisory T8044 for GnuPG and Gpg4win   important
H3 Debian packages for 2.5.16 are available (2026-01-06)
H3 GnuPG 2.5.16 released (2025-12-30)
H3 GnuPG 2.5.14 released (2025-11-19)
H3 GnuPG 2.5.13 and gpg4win 5.0.0-beta395 released (2025-10-22)
H3 GnuPG 2.5.12 released (2025-09-02)
H3 New GnuPG merchandise available (2025-09-01)
H3 GnuPG 2.5.9 with Debian packages released (2025-07-14)
H3 GnuPG 2.5.8 released (2025-05-20)
H3 GnuPG 2.5.6 and Gpg4win 5.0.0-Beta190 released (2025-05-09)
H3 GnuPG 2.5.5 and Gpg4win 5.0.0-beta145 released (2025-03-10)
H3 GnuPG 2.5.2 and Gpg4win 5.0.0-Beta32 released (2024-12-06)
H3 GnuPG 2.4.7 and Gpg4win 4.4.0 released (2024-11-27)
H3 GnuPG 2.4.6 released (2024-10-29)
H3 GnuPG 2.5.1 released with FIPS-203 support (2024-09-12)
H3 Our FTP server has been discontinued (2024-08-20)
H3 GnuPG 2.5.0 released for public testing (2024-07-05)
H3 Libgcrypt 1.11 is the new stable branch (2024-06-19)
H3 GnuPG 2.4.5 and Gpg4win 4.3.1 released (2024-03-12)
H3 Security advisory for smartcard keys with backup   important
H3 GnuPG 2.4.4 released (2024-01-25)
NAV_HEADER_HEADING_REPEATED The GNU Privacy Guard (https://gnupg.org/index.html)
Title

The GNU Privacy Guard

H2 The GNU Privacy Guard
H2 Reconquer your privacy
H2 News
H3 GnuPG 2.5.20 released (2026-05-13)
H3 GnuPG 2.5.19 released (2026-04-24)
H3 Security advisory T8211 for Libgcrypt (2026-04-21)   important
H3 Libgcrypt 1.12 is the new stable branch (2026-01-29)
H3 Security advisory T8044 for GnuPG and Gpg4win   important
H3 Debian packages for 2.5.16 are available (2026-01-06)
H3 GnuPG 2.5.16 released (2025-12-30)
H3 GnuPG 2.5.14 released (2025-11-19)
H3 GnuPG 2.5.13 and gpg4win 5.0.0-beta395 released (2025-10-22)
H3 GnuPG 2.5.12 released (2025-09-02)
H3 New GnuPG merchandise available (2025-09-01)
H3 GnuPG 2.5.9 with Debian packages released (2025-07-14)
H3 GnuPG 2.5.8 released (2025-05-20)
H3 GnuPG 2.5.6 and Gpg4win 5.0.0-Beta190 released (2025-05-09)
H3 GnuPG 2.5.5 and Gpg4win 5.0.0-beta145 released (2025-03-10)
H3 GnuPG 2.5.2 and Gpg4win 5.0.0-Beta32 released (2024-12-06)
H3 GnuPG 2.4.7 and Gpg4win 4.4.0 released (2024-11-27)
H3 GnuPG 2.4.6 released (2024-10-29)
H3 GnuPG 2.5.1 released with FIPS-203 support (2024-09-12)
H3 Our FTP server has been discontinued (2024-08-20)
H3 GnuPG 2.5.0 released for public testing (2024-07-05)
H3 Libgcrypt 1.11 is the new stable branch (2024-06-19)
H3 GnuPG 2.4.5 and Gpg4win 4.3.1 released (2024-03-12)
H3 Security advisory for smartcard keys with backup   important
H3 GnuPG 2.4.4 released (2024-01-25)
NAV_HEADING_REPEATED_FOOTER index (https://gnupg.org/blog/index.html)
Title

index

H1 The GnuPG blog
H2 Why Some Criticisms Matters More Than Others
H2 List of all blog entries
H2 Comments
H3 The Fearmongers
H3 The Half-Truth Dealers
H3 Ivory Towerism
H3 The Honest Brokers
HEADING_FOOTER GnuPG – Copying (https://gnupg.org/copying.html)
Title

GnuPG – Copying

H2 Copying
H3 Remarks
📝 The Narrative — clean text per page (Info Density · Semantic Coherence)
HOMEPAGE (https://gnupg.org) The GNU Privacy Guard
[H2] The GNU Privacy Guard
GnuPG is a complete and free implementation of the OpenPGP standard as
defined by RFC4880 (also known as PGP). GnuPG allows you to encrypt and
sign your data and communications; it features a versatile key management
system, along with access modules for all kinds of public key
directories. GnuPG, also known as GPG, is a command line tool with
features for easy integration with other applications. A wealth of
frontend applications and libraries are available. GnuPG also
provides support for S/MIME and Secure Shell (ssh).
Since its introduction in 1997, GnuPG is Free Software (meaning that
it respects your freedom). It can be freely used, modified and
distributed under the terms of the GNU General Public License .
The current version of GnuPG is 2.5.20. See the download
page for other maintained versions.
Gpg4win is a Windows version of GnuPG featuring a context menu tool, a
crypto manager, and an Outlook plugin to send and receive standard
PGP/MIME mails. The current version of Gpg4win is 5.0.2.
[H2] Reconquer your privacy
Arguing that you don't care about the right to privacy
because you have nothing to hide is no different from
saying you don't care about free speech because you have
nothing to say. – Edward Snowden
Using encryption helps to protect your privacy and the privacy of the
people you communicate with. Encryption makes life difficult for bulk
surveillance systems. GnuPG is one of the tools that Snowden used to
uncover the secrets of the NSA.
Please visit the Email Self-Defense site to learn how and why you
should use GnuPG for your electronic communication.
[H2] News
The latest blog entries:
Why Some Criticisms Matters More Than OthersCleartext Signatures Considered HarmfulNew GnuPG Repositories for Debian, Ubuntu, and Devuan: Stable and Development Branches Available
The latest release news:
(all news)
[H3] GnuPG 2.5.20 released (2026-05-13)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.20. This version adds two features to gpgsm and fixes a
some minor security bugs. {Read more}
[H3] GnuPG 2.5.19 released (2026-04-24)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.19. This release adds a few new features and fixes a
couple of bugs. {Read more}
[H3] Security advisory T8211 for Libgcrypt (2026-04-21)   important
A security bug which can be used to mount a DoS attack on Libgcrypt
has been reported. New versions of Libgcrypt have been released to
fix this bug: Libgcrypt 1.12.2, 1.11.3, and 1.10.4.
Note that the current stable GnuPG version is not affected.
{Read more}
[H3] Libgcrypt 1.12 is the new stable branch (2026-01-29)
Although we will keep on maintaining the 1.11 branch for two more
years, the new stable and LTS branch is now 1.12. Version 1.12.0
comes with some performance improvements and new interfaces to better
support FIPS requirements. It provides full API and ABI compatibility
to previous versions. {more}
[H3] Security advisory T8044 for GnuPG and Gpg4win   important
GnuPG 2.5.17 and Gpg4win 5.0.1 have been released to fix a severe
security bug in GnuPG versions 2.5.13 to 2.5.16. Please update as
soon as possible.
{Read more}
[H3] Debian packages for 2.5.16 are available (2026-01-06)
GnuPG 2.5.16 packages for Debian, Devuan, and Ubuntu are now available
at their usual place repos.gnupg.org - please consider to update.
[H3] GnuPG 2.5.16 released (2025-12-30)
We are pleased to announce the availability of a new stable GnuPG release:
Version 2.5.16. This release adds new features and fixes a couple of
bugs.
Note that the 2.5 series is now declared the stable version of GnuPG.
Be aware that the oldstable 2.4 series will reach end-of-life in just
6 months.
{Read more}
[H3] GnuPG 2.5.14 released (2025-11-19)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.14. This release adds new features and fixes a couple of
bugs. New Debian packages are also also availabe; see
repos.gnupg.org.
Note that this 2.5 series is fully supported and thus ready for
production use. This means we won't break anything but may add some
more features before 2.6.
{Read more}
[H3] GnuPG 2.5.13 and gpg4win 5.0.0-beta395 released (2025-10-22)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.13. This release adds new features and fixes a couple of
bugs.
Along with this GnuPG version we also released a another beta
version of Gpg4win 5.0.
Note that this 2.5 series is fully supported and thus ready for
production use. This means we won't break anything but may add some
more features before 2.6.
{Read more}
[H3] GnuPG 2.5.12 released (2025-09-02)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.12. This release adds new features and fixes two
regressions.
Note that this 2.5 series is fully supported and thus ready for
production use. This means we won't break anything but may add some
more features before 2.6.
{Read more}
[H3] New GnuPG merchandise available (2025-09-01)
We have launched a new web shop where you can find merchandise to show
your support for GnuPG. We have been planning to offer merchandise
again for a long time, and this print-on-demand service enables us to
offer a wide range of products, so we hope there is something for
everyone. Please contact us if you can't find what you're looking
for. You can get a 25% discount for orders within the next 9 days!
[H3] GnuPG 2.5.9 with Debian packages released (2025-07-14)
We are pleased to announce the availability of a new GnuPG release.
Version 2.5.9 which will soon lead us to the new stable 2.6 series.
This release mostly fixes regression in the previous releases. We now
also provide packages for Debian, Devuan, and Ubuntu in addition to
the usual Gpg4win beta installer.
{Read more}
[H3] GnuPG 2.5.8 released (2025-05-20)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.8. This release is another one in a series of public
testing releases eventually leading to a new stable version 2.6. Do
not hesitate to use this new version; it is fully functional and
maintained.
{Read more}
[H3] GnuPG 2.5.6 and Gpg4win 5.0.0-Beta190 released (2025-05-09)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.6. This release is the third of a series of public
testing releases eventually leading to a new stable version 2.6.
Along with this GnuPG version we also released another beta
version of Gpg4win 5.0.
{Read more}
[H3] GnuPG 2.5.5 and Gpg4win 5.0.0-beta145 released (2025-03-10)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.5. This release fixes a couple of problems found in the
previous 2.5 versions.
Along with this GnuPG version we also released another beta version
of Gpg4win 5.0.
{Read more}
[H3] GnuPG 2.5.2 and Gpg4win 5.0.0-Beta32 released (2024-12-06)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.2. This release is the third of a series of public
testing releases eventually leading to a new stable version 2.6.
Along with this GnuPG version we also released a first beta version
of Gpg4win 5.0.
{Read more}
[H3] GnuPG 2.4.7 and Gpg4win 4.4.0 released (2024-11-27)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.7. This version fixes a couple of bugs. Along
with this release we also released a new version of Gpg4win: version
4.4.0.
{Read more}
[H3] GnuPG 2.4.6 released (2024-10-29)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.6. This version fixes a couple of bugs, comes
with a few new features, and has now full support for Portuguese.
{Read more}
[H3] GnuPG 2.5.1 released with FIPS-203 support (2024-09-12)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.1. This release is the second of a series of public
testing releases eventually leading to a new stable version 2.6.
The main features in the 2.6 series are improvements for 64 bit
Windows and the introduction of a PQC encryption algorithm.
{Read more}.
[H3] Our FTP server has been discontinued (2024-08-20)
For technical and organisational reasons we recently shutdown our FTP
server. Instead of using ftp.gnupg.org please use
https://gnupg.org/ftp/ .
[H3] GnuPG 2.5.0 released for public testing (2024-07-05)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.0. This release is the first of a series of public testing
releases eventually leading to a new stable version 2.6.
The main features in the 2.6 series are improvements for 64 bit
Windows and the introduction of a PQC encryption algorithm.
{Read more}.
[H3] Libgcrypt 1.11 is the new stable branch (2024-06-19)
Although we will keep on maintaining the 1.8 and 1.10 branch for some
more time, the new stable branch is now 1.11. Version 1.11.0 comes
with a lot of performance improvements, new interfaces, and now
supports common quantum-resistant algorithms. It provides full API
and ABI compatibility to previous versions. {more}
[H3] GnuPG 2.4.5 and Gpg4win 4.3.1 released (2024-03-12)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.5. This version fixes a couple of bugs and comes
with some new features. {more}
[H3] Security advisory for smartcard keys with backup   important
GnuPG versions 2.4.2, 2.4.3, and 2.2.42 had a regression in the
default way to create smartcard keys. If you created a key with the
–edit-key command using one of these versions, please head over to
our security advisory:
https://gnupg.org/blog/20240125-smartcard-backup-key.html
[H3] GnuPG 2.4.4 released (2024-01-25)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.4. This version fixes a couple of bugs, comes
with some new features. A smartcard related security bug is also
fixed and a tool to check for this flaw is provided. {more}
9940 chars
SUB-PAGE (https://gnupg.org/index.html) The GNU Privacy Guard
[H2] The GNU Privacy Guard
GnuPG is a complete and free implementation of the OpenPGP standard as
defined by RFC4880 (also known as PGP). GnuPG allows you to encrypt and
sign your data and communications; it features a versatile key management
system, along with access modules for all kinds of public key
directories. GnuPG, also known as GPG, is a command line tool with
features for easy integration with other applications. A wealth of
frontend applications and libraries are available. GnuPG also
provides support for S/MIME and Secure Shell (ssh).
Since its introduction in 1997, GnuPG is Free Software (meaning that
it respects your freedom). It can be freely used, modified and
distributed under the terms of the GNU General Public License .
The current version of GnuPG is 2.5.20. See the download
page for other maintained versions.
Gpg4win is a Windows version of GnuPG featuring a context menu tool, a
crypto manager, and an Outlook plugin to send and receive standard
PGP/MIME mails. The current version of Gpg4win is 5.0.2.
[H2] Reconquer your privacy
Arguing that you don't care about the right to privacy
because you have nothing to hide is no different from
saying you don't care about free speech because you have
nothing to say. – Edward Snowden
Using encryption helps to protect your privacy and the privacy of the
people you communicate with. Encryption makes life difficult for bulk
surveillance systems. GnuPG is one of the tools that Snowden used to
uncover the secrets of the NSA.
Please visit the Email Self-Defense site to learn how and why you
should use GnuPG for your electronic communication.
[H2] News
The latest blog entries:
Why Some Criticisms Matters More Than OthersCleartext Signatures Considered HarmfulNew GnuPG Repositories for Debian, Ubuntu, and Devuan: Stable and Development Branches Available
The latest release news:
(all news)
[H3] GnuPG 2.5.20 released (2026-05-13)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.20. This version adds two features to gpgsm and fixes a
some minor security bugs. {Read more}
[H3] GnuPG 2.5.19 released (2026-04-24)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.19. This release adds a few new features and fixes a
couple of bugs. {Read more}
[H3] Security advisory T8211 for Libgcrypt (2026-04-21)   important
A security bug which can be used to mount a DoS attack on Libgcrypt
has been reported. New versions of Libgcrypt have been released to
fix this bug: Libgcrypt 1.12.2, 1.11.3, and 1.10.4.
Note that the current stable GnuPG version is not affected.
{Read more}
[H3] Libgcrypt 1.12 is the new stable branch (2026-01-29)
Although we will keep on maintaining the 1.11 branch for two more
years, the new stable and LTS branch is now 1.12. Version 1.12.0
comes with some performance improvements and new interfaces to better
support FIPS requirements. It provides full API and ABI compatibility
to previous versions. {more}
[H3] Security advisory T8044 for GnuPG and Gpg4win   important
GnuPG 2.5.17 and Gpg4win 5.0.1 have been released to fix a severe
security bug in GnuPG versions 2.5.13 to 2.5.16. Please update as
soon as possible.
{Read more}
[H3] Debian packages for 2.5.16 are available (2026-01-06)
GnuPG 2.5.16 packages for Debian, Devuan, and Ubuntu are now available
at their usual place repos.gnupg.org - please consider to update.
[H3] GnuPG 2.5.16 released (2025-12-30)
We are pleased to announce the availability of a new stable GnuPG release:
Version 2.5.16. This release adds new features and fixes a couple of
bugs.
Note that the 2.5 series is now declared the stable version of GnuPG.
Be aware that the oldstable 2.4 series will reach end-of-life in just
6 months.
{Read more}
[H3] GnuPG 2.5.14 released (2025-11-19)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.14. This release adds new features and fixes a couple of
bugs. New Debian packages are also also availabe; see
repos.gnupg.org.
Note that this 2.5 series is fully supported and thus ready for
production use. This means we won't break anything but may add some
more features before 2.6.
{Read more}
[H3] GnuPG 2.5.13 and gpg4win 5.0.0-beta395 released (2025-10-22)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.13. This release adds new features and fixes a couple of
bugs.
Along with this GnuPG version we also released a another beta
version of Gpg4win 5.0.
Note that this 2.5 series is fully supported and thus ready for
production use. This means we won't break anything but may add some
more features before 2.6.
{Read more}
[H3] GnuPG 2.5.12 released (2025-09-02)
We are pleased to announce the availability of a new GnuPG release:
Version 2.5.12. This release adds new features and fixes two
regressions.
Note that this 2.5 series is fully supported and thus ready for
production use. This means we won't break anything but may add some
more features before 2.6.
{Read more}
[H3] New GnuPG merchandise available (2025-09-01)
We have launched a new web shop where you can find merchandise to show
your support for GnuPG. We have been planning to offer merchandise
again for a long time, and this print-on-demand service enables us to
offer a wide range of products, so we hope there is something for
everyone. Please contact us if you can't find what you're looking
for. You can get a 25% discount for orders within the next 9 days!
[H3] GnuPG 2.5.9 with Debian packages released (2025-07-14)
We are pleased to announce the availability of a new GnuPG release.
Version 2.5.9 which will soon lead us to the new stable 2.6 series.
This release mostly fixes regression in the previous releases. We now
also provide packages for Debian, Devuan, and Ubuntu in addition to
the usual Gpg4win beta installer.
{Read more}
[H3] GnuPG 2.5.8 released (2025-05-20)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.8. This release is another one in a series of public
testing releases eventually leading to a new stable version 2.6. Do
not hesitate to use this new version; it is fully functional and
maintained.
{Read more}
[H3] GnuPG 2.5.6 and Gpg4win 5.0.0-Beta190 released (2025-05-09)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.6. This release is the third of a series of public
testing releases eventually leading to a new stable version 2.6.
Along with this GnuPG version we also released another beta
version of Gpg4win 5.0.
{Read more}
[H3] GnuPG 2.5.5 and Gpg4win 5.0.0-beta145 released (2025-03-10)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.5. This release fixes a couple of problems found in the
previous 2.5 versions.
Along with this GnuPG version we also released another beta version
of Gpg4win 5.0.
{Read more}
[H3] GnuPG 2.5.2 and Gpg4win 5.0.0-Beta32 released (2024-12-06)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.2. This release is the third of a series of public
testing releases eventually leading to a new stable version 2.6.
Along with this GnuPG version we also released a first beta version
of Gpg4win 5.0.
{Read more}
[H3] GnuPG 2.4.7 and Gpg4win 4.4.0 released (2024-11-27)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.7. This version fixes a couple of bugs. Along
with this release we also released a new version of Gpg4win: version
4.4.0.
{Read more}
[H3] GnuPG 2.4.6 released (2024-10-29)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.6. This version fixes a couple of bugs, comes
with a few new features, and has now full support for Portuguese.
{Read more}
[H3] GnuPG 2.5.1 released with FIPS-203 support (2024-09-12)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.1. This release is the second of a series of public
testing releases eventually leading to a new stable version 2.6.
The main features in the 2.6 series are improvements for 64 bit
Windows and the introduction of a PQC encryption algorithm.
{Read more}.
[H3] Our FTP server has been discontinued (2024-08-20)
For technical and organisational reasons we recently shutdown our FTP
server. Instead of using ftp.gnupg.org please use
https://gnupg.org/ftp/ .
[H3] GnuPG 2.5.0 released for public testing (2024-07-05)
We are pleased to announce the availability of a new GnuPG release:
version 2.5.0. This release is the first of a series of public testing
releases eventually leading to a new stable version 2.6.
The main features in the 2.6 series are improvements for 64 bit
Windows and the introduction of a PQC encryption algorithm.
{Read more}.
[H3] Libgcrypt 1.11 is the new stable branch (2024-06-19)
Although we will keep on maintaining the 1.8 and 1.10 branch for some
more time, the new stable branch is now 1.11. Version 1.11.0 comes
with a lot of performance improvements, new interfaces, and now
supports common quantum-resistant algorithms. It provides full API
and ABI compatibility to previous versions. {more}
[H3] GnuPG 2.4.5 and Gpg4win 4.3.1 released (2024-03-12)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.5. This version fixes a couple of bugs and comes
with some new features. {more}
[H3] Security advisory for smartcard keys with backup   important
GnuPG versions 2.4.2, 2.4.3, and 2.2.42 had a regression in the
default way to create smartcard keys. If you created a key with the
–edit-key command using one of these versions, please head over to
our security advisory:
https://gnupg.org/blog/20240125-smartcard-backup-key.html
[H3] GnuPG 2.4.4 released (2024-01-25)
We are pleased to announce the availability of a new stable GnuPG
release: version 2.4.4. This version fixes a couple of bugs, comes
with some new features. A smartcard related security bug is also
fixed and a tool to check for this flaw is provided. {more}
9940 chars
SUB-PAGE (https://gnupg.org/blog/index.html) index
[H1] The GnuPG blog
[H2] Why Some Criticisms Matters More Than Others
Posted March 30, 2026 by Robert J. Hansen
On the GnuPG-Users mailing list, a user asked the following
(paraphrased) question:
I am very well aware of the consistent and persistent campaign against
GnuPG. Is there a reason for this?
There are many reasons.
Before we go further, the things I'm speaking of apply to both LibrePGP
and RFC9580 OpenPGP. The criticisms made against one usually wind up
getting made against the other, whether for good or ill. These
criticisms fall on a spectrum, from infuriatingly dishonest all the way
to carefully thought out and researched. I'll start with the ones I
think are dishonest.
[H3] The Fearmongers
The worst of the worst, my personal bête noire, come from a particular
kind of user: someone who derives their social status from the unholy
union of
being a geek and
making people afraid.
When you can make people afraid you can lead them into looking to you to
tell them what to do. Making people afraid is usually a power play of
some kind. It reminds me of high school.
What pushes me over the edge into being a genuinely unpleasant person is
when they make people afraid about something they can't verify for
themselves. When Chicken Little told everyone the sky was falling, at
least Chicken Little had the common decency to lie about something
people could disprove just by looking up.
There are a lot of nerdy people making people scared about near-future
events they have to take on faith. I don't see much difference between
Sam Altman telling people "in eighteen months half of your jobs will be
gone!" and somebody hiding behind a pseudonym saying "ackshually the new
NSA listening center in Utah is going to be able to crack PGP
because…". Either way it's the same spiel. These people make me very
angry.
[H3] The Half-Truth Dealers
Then there are the people who deal in half-truth criticisms. For
instance, a lot of people say that Open/LibrePGP don't offer forward
secrecy, and "all modern designs offer perfect forward secrecy."
Forward secrecy (sometimes misnamed "perfect" forward secrecy) relates
to a property of cryptosystems where compromising one message doesn't
help you compromise other messages in the past or future. ClassicPGP
offered this all the way back in 1991. Each message is encrypted with
its own unique session key: if I give you that unique session key it
does not help you decrypt any other message. Presto: Libre and OpenPGP
have both had forward secrecy since their moment of conception.
Some of you may be thinking, "yes, but if a long-term key is compromised
that's a terrible problem: do Libre and OpenPGP really offer forward
secrecy?"
And you're correct: what I said was a half-truth. Looked at one way
Libre and OpenPGP offer forward secrecy, but there's a very important
way in which they don't. Clearly, we shouldn't talk about Libre and
OpenPGP like this. We should talk fairly, in complete truths.
Now you know why I get so ornery when people insist "Libre and OpenPGP
use long-term keys, so there's no forward secrecy." It's a half-truth at
best, and it obscures important things about how the system operates.
Half-truth dealers are found everywhere in computer security
discussions. Some of them are innocently miseducated: these people
should be corrected kindly and respectfully. Some are genuinely engaging
in bad faith: these people should be called out.
[H3] Ivory Towerism
Then there are academics who make highly academic criticisms, that
although are offered in good faith often show a lack of consideration of
real-world constraints on what we can do, or a lack of understanding of
what the real problems are.
For instance, from RFC2440 to the final draft of RFC4880, OpenPGP
specified 3DES as a permissible algorithm. 3DES was designed in the
1970s and is by modern standards unbearably ugly. It has all the
aesthetic qualities of Soviet New Realism art coupled with all the
elegance of a North Korean workers' housing bloc.
But you'll notice I never said 3DES was weak. After fifty years (!!) of
cryptanalytical research nobody knows of any practical attacks on 3DES
when used in the standard OpenPGP use case. It's kind of impressive that
way.
Despite this brilliant record of resistance to cryptanalysis (when used
in the standard use case) a lot of academic critics continue to smear it
— and other technology choices within Libre and OpenPGP — as somehow
being weak because it is ugly.
I respectfully disagree. I don't think these critics are being
dishonest, but I wonder what causes them to confuse strength with
beauty.
[H3] The Honest Brokers
Some very serious people have made very serious criticisms of OpenPGP
over the years. Matthew Green at Johns Hopkins, for starters, was really
not a fan. See, for instance,
his essay at Cryptography Engineering.
He made those criticisms in 2014. They were devastatingly sharp and
overwhelmingly fair. As a consequence, Libre/OpenPGP took notice. The
latest specifications mitigate the majority of his concerns from 2014. I
doubt he's since become a fan, but Libre/OpenPGP deserve credit for
being willing to listen to a passionate critic speaking in good faith.
I think we need more critics like Matthew Green. As hard as it is to
hear honest and well-founded "this is why nobody uses Libre/OpenPGP"
criticism, I'm always grateful for it. That's how we get better.
But for every solid, well-thought-out, and occasionally devastating
critique on Open/LibrePGP there are easily a dozen ones that vary from
disingenuous to confused to genuinely dishonest and manipulative.
This essay is © 2026 by Robert J. Hansen. You may use it under the
Creative Commons Attribution-NoDerivs 4.0 license.
[H2] List of all blog entries
Why Some Criticisms Matters More Than Others
Cleartext Signatures Considered Harmful
New GnuPG Repositories for Debian, Ubuntu, and Devuan: Stable and Development Branches Available
Sequoias need for churn
Smartcard generation keeps an unprotected backup key on disk
ADSK: The Additional Decryption Subkey
Integer Overflow in LibKSBA / GnuPG
A New Future for GnuPG
Using a TPM with GnuPG 2.3
GnuPG and LDAP
Using an OpenPGP card in the UbuntuPhone BQ E4.5
Financial Results for 2016
Using the Web Key Service with Enigmail
Using the Web Key Service with Enigmail
Independent Encryption Software, GnuPG, Needs Financial Support
A New Bugtracker for GnuPG
GnuPG this Past Fall
Hosting a Web Key Directory
GnuPG this Past Summer
Python bindings for GPGME
OpenPGP.conf: A Success
Key Discovery Made Simple
GnuPG in 2016
Financial Results for 2015
GnuPG News for November and December 2015
GnuPG News for September and October 2015
GnuPG News for Summer 2015
GnuPG News for May 2015
GnuPG News for March and April 2015
Notes from the first OpenPGP Summit
GnuPG News for February 2015
GnuPG News for January 2015
Happy gnu year
GnuPG and g10code
Goteo Campaign: Preliminary Results
Mission complete: campaign ends, closing stats
Find us at FOSDEM
How good is Goteo? An appraisal
16 Years of protecting privacy
Press release: GnuPG encryption project launches crowdfunding campaign
Getting Goteo approval
Speedups in Libgcrypt 1.6
Preparing for launch
Friends tell friends they love GnuPG
Securing the future of GPG
New blog, first post
[H2] Comments
We do not provide a feature to comment on a blog. Instead please
send remarks to the gnupg-users mailing list using the blog title
for the subject line. This helps to keep the discussion at one
place and not to spread it over different media.
7577 chars
SUB-PAGE (https://gnupg.org/copying.html) GnuPG – Copying
[H2] Copying
Except when noted otherwise, these web pages are copyrighted by The
GnuPG Project. Given that such a legal entity does not exist, that
name should be considered a placeholder for the list of the actual
authors:
© 1998–2018 Werner Koch
© 2000–2002 Nils Ellmenreich
© 2001–2002 Mike Ashley
© 2002–2005 Lorenzo Cappelletti
© 2006–2006 David Shaw
© 2006 Thomas Wittek
© 2017–2018 Ben McGinnes
You can redistribute these pages and/or modify them under the terms
of the
Creative Commons Attribution-ShareAlike 3.0 Unported License
or alternatively under the terms of the
GNU General Public License as published by the Free Software
Foundation; either version 3 of the License, or (at your option)
any later version.
If you wish to allow the use of your version of these pages only
under the terms of one of these licenses, indicate your decision by
deleting the respective above paragraph.
The canonical version of the logo can be found in the GnuPG code
repository; see its README file for details.
[H3] Remarks
For many years we maintained translation of these pages to French,
German, Italian, and Spanish. A big thank you to the translators:
Jean-Francois Paris, Walter Koch, Cristian Rigamonti, and Noel
David Torres Taño. Because we didn’t always managed to keep those
translation up to date, we decided in 2013 to abandon them. In
case translations are again demanded by users and sufficient
resources are available, the tentative plan is to setup individual
sites per language with language or country specific information.
Former version of these web pages have been marked as copyrighted
by the Free Software Foundation. However, a formal act to
transfer the copyright to them has never been conducted. Thus in
2013 these notices have been replaced by a reference to the list of
individual copyright holders.
1825 chars
🛡️ Trust Signals — reviews, proof links, trust-theatre flag (Trust & Proof)
0Review mentions (all pages)
0External proof links (all pages)
PageReviewsProof links
/ (home) 0 0
/index.html 0 0
/blog/index.html 0 0
/copying.html 0 0
🔗 Identity & Technical Layer — schema JSON-LD: identity chains, entity gaps (Identity & Authority)
Homepage — no schema detected (entity gap)
/index.html — no schema detected (entity gap)
/blog/index.html — no schema detected (entity gap)
/copying.html — no schema detected (entity gap)

Your Diagnosis

Before revealing the machine’s verdict, predict the BS score for each signal. Higher = more BS (more fluff, less verifiable substance). Drag each slider, then submit to compare your judgment against the engine.

Information Density 0 / 30
Read the Narrative & headings: do hard facts (prices, dates, numbers) outweigh fluff power-words?
Semantic Coherence 0 / 20
Compare the homepage promise against the sub-page reality. Do they hold the same line?
Trust & Proof 0 / 20
Weigh review mentions against actual external proof links. Claims without verification = theatre.
Commodity Fingerprint 0 / 15
Check headings & narrative against the industry clichés in the setup above.
Identity & Authority 0 / 15
Inspect the schema: is there real Organization/Person identity with sameAs links, or gaps?
Your predicted BS score 0 / 100
💡 Stuck? Reveal the heuristic lens — how the deterministic page-auditor reads each signal (no AI, pure pattern rules)

These are the structural rules a local, deterministic auditor applies — the same lens you can use to judge each signal. They describe what to look for, not this company’s result.

Information Density

Classify each sentence as substantive or hollow. Grounding markers — numbers, currencies, dates, technical units, named entities — outweigh marketing adjectives. When fluff sits right next to hard evidence, the fluff is forgiven.

Semantic Alignment

Pull the main entities out of the H1, then check whether they actually recur through the body. A page that announces one thing and then talks about another drifts. Headings with no real sentences underneath read as pseudo-substance.

Trust & Proof

Count trust words (review, testimonial, rating, verified) against real outbound proof links (Google, Trustpilot, Clutch, G2, Yelp). Lots of trust language with zero verification links is trust theatre. Unlinked logo galleries count against it.

Commodity Fingerprint

Look at how much sentence length varies. Natural writing varies its rhythm; templated or mass-produced copy is statistically uniform. Very low variation reads as commodity content — unless unique named entities break the pattern.

Identity & Authority

Inspect the JSON-LD. Is there an Organization or Person schema, and does it carry sameAs links to real external profiles (LinkedIn, socials)? Missing schema or no identity declaration signals an anonymous entity.

Want to apply this lens yourself? The free BS Indicator Chrome extension runs these heuristic checks live on any page. Bear in mind it is a single-page, deterministic tool — it relies only on pattern rules for the page in front of it and does not perform the cross-page semantic correlation this audit uses, so its readout is a starting lens, not the full verdict.

B
BS Level
Security, Surveillance & Cybersecurity
36.5 Avg BS

Based on 370 businesses audited.

BS Detector

Security, Surveillance & Cybersecurity BS: GnuPG (The GNU Privacy Guard) (gnupg.org)

https://gnupg.org 📍 Industry: Security, Surveillance & Cybersecurity
4 BS / 100

This is a benchmark for zero-BS technical communication. GnuPG.org ignores modern marketing trends entirely, providing a substance-heavy environment where the product’s code and transparency serve as the primary proof of value. It is a high-utility technical resource with almost no forensic evidence of bullshit.

Info Density Power-words vs. Substance ratio.
1
3% BS
Semantic Coherence Homepage promise vs. Sub-page reality.
0
0% BS
Trust & Proof Verifiable evidence vs. Trust Theatre.
1
5% BS
Commodity Fingerprint Detection of industry clichés/templates.
0
0% BS
Identity & Authority Expert verifiability & Schema depth.
2
13% BS

Implement Organization and SoftwareApplication JSON-LD schema to formally link the project to its founders and technical specifications. Add outbound links to external verification for the Snowden claim to satisfy zero-trust verification standards. Include a dedicated ‘Team’ page with Person schema for the authors listed in the copyright section to bridge the minor identity footprint gap. Ensure that all security advisory ‘read more’ links lead to an on-site CVE archive for better audit trails.

The site is a perfect match for the Cybersecurity industry, specifically focusing on cryptographic software and privacy tools. Unlike corporate sites, it functions as a technical documentation hub and software repository, prioritizing technical standards like RFC4880 over marketing rhetoric.

“The score of 4 is driven primarily by the lack of structured data (Schema) and a single unsubstantiated (though factually correct) claim regarding Edward Snowden. The site achieves a near-perfect result in information density and semantic coherence, with zero industry cliché matches. It is one of the least 'bullshit' sites in the cybersecurity sector.”

Verified Analysis Date: May 26, 2026 © 1EuroSEO Independent Evaluator — Non-Sponsored Result
Brand AI Reputation