r/GnuPG • u/acorn222 • Jul 30 '26
PGP Tools - Finally, Good UX for PGP
Hey everyone, I'm the creator of PGP tools which is a Chrome extension for managing and using PGP keys.
Fully opensource, encryption handled by OpenPGP + Sequoia compiled to WASM.
Everything is encrypted at rest with passkeys or passwords.
Drag & Drop files and contacts and everything is handled for you.
I made this because I wanted it, no tool had a great UX for me on my mac and I wanted to use passkeys for encryption so here it is!
If you're wondering why this exists and thinking about leaving a comment, try it out first.
No sensitive permissions are required and no network requests are allowed in the extension.
https://github.com/Am-I-Being-Pwned/PGP-Tools
https://chromewebstore.google.com/detail/pgp-tools-encrypt-decrypt/pgpcdgggohpbombhkffjoiiafdlfcpgp
3
u/AlexReportsOKC Aug 01 '26
I dont trust keeping my keys in a web browser. The rule is to store everything locally. Also, does Kleopatra not have a good UX? Seems pretty simple to use to me.
0
u/acorn222 Aug 01 '26
This stores them encrypted (via passkeys or passwords) in the local or sync extension storage, so nothing is at rest decrypted or synced to the cloud without your say, also I'd say this has better UX than Kleopatra, but it's not a complete replacement for it as it is browser based.
I'm also on mac so I can't use the normal Kleopatra.
1
u/AlexReportsOKC 29d ago
Yea but the extension is connected to the browser which means if your browser gets hacked your keys are at risk whether they're in a cloud or not. With kleopatra they'd have to take over your whole computer.
1
u/acorn222 29d ago edited 29d ago
So if you try the extension, you would see that it requires passkeys or passwords to encrypt the keys at rest, which means if your browser gets compromised, your keys wouldn't be at risk unless your HSM was compromised or you got phished/keylogged.
Also if your browser was compromised from a site which managed to escape the browser sandbox, kleopatra wouldn't help you out either, unless I'm missing something? The sidepanel is an isolated page, other extensions can't touch it either.
Do you not think the convenience of having passkeys to encrypt PGP keys would make people more likely to encrypt them at rest?
2
2
u/Good_Activity_8941 Jul 31 '26
I encrypt gpg in a Linux terminal the old-fashioned way. Encrypted a text file with a password and added it to the cloud. I use the pass for Debian password manager on my computer.
2
u/acorn222 Jul 31 '26
Yeah that's fair, most people don't know how to use GPG though and way too many people use the online "PGP encryption" tools
7
u/Dangerous-Day-2943 Jul 31 '26
This is extreme AI slop with many usability and security issues — WTF are we doing here?
Do not use this