Should I be using gpg or gpg2?

Werner Koch wk at
Mon Sep 28 19:40:00 CEST 2015

On Mon, 28 Sep 2015 13:23, listofactor at said:

> Unless you have specific reasons for transitioning to gpg2, stick
> with gpg (GnuPG) 1.4.16. It is just as secure, and much easier

That is definitely not the case.  All improvements go into 2.1 and some
are backported to 2.0.  We only add necessary fixes to 1.4.  The crypto
code in 1.4 is way older than what we use in 2.0 - over there we use
Libgcrypt which has received a lot more attention than the old code in
1.4 and it is much faster for large data.

BTW, the close to 2 years old 1.4.16 misses a couple of security fixes
and should asap be updated to 1.4.19.



Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.

More information about the Gnupg-users mailing list