Cipher Preferences Ignored for Kyber keys?

Robert J. Hansen rjh at sixdemonbag.org
Mon Jul 27 18:59:47 CEST 2026


> Twofish was an AES candidate which did not make it.  Camellia was
> included for pure political reasons.

For others who wonder:

IDEA was included for PGP 2.6 support. In 1993 IDEA was a pretty good
option for civilian cryptography. It hasn't really been a defensible
choice for anything since '98 or so. We still support it.

3DES was included because back in the mid-'90s during PGP 5 development
there was some concern over the IDEA algorithm being patented and PRZ
wanting an emergency last-ditch fallback.

CAST5 was included because PGP 5 used it as a default instead of the
patented IDEA. There's been no real cause for it since '99.

BLOWFISH was included because ... ? Nobody's ever explained that to me
except to vaguely say "patents". It was there in GnuPG 1.0 and PGP 7,
both dating from '99-'00, and has never really been needed.

TWOFISH came about because in '99 some PGP financial backers were really
getting nervous over how PGP 5 was dependent on patented algorithms. PRZ
was under a lot of pressure to add a patent-free modern cipher,
preferably with government backing, to PGP. The AES competition was
underway and TWOFISH was a front-runner. PRZ gambled TWOFISH would
become AES, and put it into PGP 7. Almost as soon as he did this
Rijndael was selected to become AES, but the press releases saying
TWOFISH was being introduced to PGP 7 had already been drafted.

DSA signatures and Elgamal encryption keys were added because PGP 5 was
still trying to get away from the RSA patent. PGP 5 misnamed them as
"Diffie-Hellman" because of some business deal with the company pushing
DSA/Elg as an RSA alternative, or so I heard.

Elgamal signatures were added because ... I am unaware of the case for
including these. It was widely regarded as a mistake.

RIPEMD160 was included because some people objected intensely to PGP 5
using SHA-1 as a hash algorithm, on the grounds SHA-1 was designed at NSA.

The cipher zoo is real. It's not an embarrassment, but ... it really is
a legacy of the software patents of the late '90s. Even today, thirty
years later, we're still seeing the consequences.

> not seen a demand for other national cipher algorithms in the last 20
> years (Despite that there are at least a Russian and a Chinese set of
> algorithms).

And Ukrainian. DSTU-7456.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 236 bytes
Desc: OpenPGP digital signature
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260727/13e25af1/attachment.sig>


More information about the Gnupg-users mailing list