PGP and GPG: The Web of Trust and Why Email Encryption Stayed Niche
PGP is a hybrid cryptosystem for encrypting and signing files and messages, and GPG is its widely used free implementation. Technically it has aged well; as an email encryption scheme it never achieved broad adoption, and the reasons are instructive about usability as a security property. How the hybrid scheme works PGP does not encrypt a message with the recipient's public key directly — asymmetric operations are far too slow for bulk data. Instead it generates a random symmetric session key, encrypts the message with that, then encrypts the session key with each recipient's public key and attaches the results. Each recipient uses their private key to recover the session key, and the session key to read the message. This is the same pattern TLS uses and the standard arrangement described under asymmetric encryption : asymmetric for key establishment, symmetric for the data. It is also why adding a recipient is cheap — one more encrypted copy of a small key rather than ...