Cryptography

PGP Encryption Explained: How It Works and Why It Still Matters

11 min read
By
PGP Encryption Explained: How It Works and Why It Still Matters

NovelCrypt

PGP is one of the most misunderstood technologies in cryptography. People think it is an encryption algorithm. It is not. PGP is a complete cryptographic system that combines three distinct technologies — symmetric encryption, asymmetric encryption, and digital signatures — into a single workflow for secure communication. Understanding how these pieces fit together reveals why PGP remains relevant 35 years after its creation.

What PGP Is

PGP (Pretty Good Privacy) is a cryptographic software system that provides confidentiality, integrity, and authentication for messages and files. It was created by Phil Zimmermann in 1991 and became one of the first practical implementations of public-key cryptography available to the general public.

PGP is not a single algorithm. When you "encrypt a message with PGP," the system performs several operations using multiple algorithms:

1. It generates a random symmetric session key. 2. It encrypts your message with that session key using a fast symmetric cipher (AES). 3. It encrypts the session key with the recipient's public key using an asymmetric cipher (RSA or ECC). 4. It packages the encrypted message and the encrypted session key together.

This is hybrid encryption — the same pattern that TLS uses for HTTPS. The asymmetric algorithm handles the key distribution problem, and the symmetric algorithm handles the bulk data at speed. For a deeper understanding of why this combination is necessary, read our symmetric vs asymmetric encryption guide and our hybrid encryption explainer.

A Brief History

Phil Zimmermann created PGP in 1991 as a response to the lack of widely available encryption for personal communication. He published it for free on the internet, and it spread rapidly.

The U.S. government responded by launching a criminal investigation against Zimmermann for exporting munitions without a license — encryption software was classified as a munition under U.S. export law at the time. The investigation lasted three years and was dropped in 1996, but not before Zimmermann published the PGP source code as a printed book, exploiting the First Amendment protections that applied to books but not to software.

This history matters because it shaped PGP's design philosophy. PGP was built for a world where encryption was controversial, governments were hostile, and trust had to be distributed rather than centralized. That philosophy produced the web of trust — PGP's decentralized key verification model — which remains unique among cryptographic systems.

The Four Components of PGP

PGP is best understood as four separate cryptographic operations that work together. Each can be used independently, but their combination is what makes PGP powerful.

### Component 1: Symmetric Encryption (AES Session Key)

When PGP encrypts a message, the actual message data is encrypted with a symmetric cipher. Modern PGP uses AES-256 by default. PGP generates a fresh random session key for each message — this key is typically 256 bits and is generated using a cryptographically secure random number generator.

The session key is the real secret that protects your message. Everything else in PGP is about securely transporting this key to the recipient. You can see how symmetric encryption works firsthand with the AES text encryptor, and read about why AES-256 is the standard in our AES-256-GCM explainer.

### Component 2: Asymmetric Key Wrapping (RSA or ECC)

The session key from Component 1 needs to reach the recipient. PGP encrypts the session key with the recipient's public key. Only the recipient's private key can decrypt it.

This is where RSA or ECC comes in. The recipient's PGP key pair is an asymmetric key pair — a public key that anyone can use to encrypt to them, and a private key that only they hold. The public key is typically distributed via key servers, email signatures, or direct exchange.

When the recipient decrypts a PGP message, they first use their private key to decrypt the session key, then use the session key to decrypt the actual message. The asymmetric operation handles a small amount of data (the 256-bit session key), and the symmetric operation handles the bulk data. You can experiment with asymmetric encryption using the RSA encrypt/decrypt tool and our RSA encryption explainer.

### Component 3: Digital Signatures

PGP does not just encrypt messages — it signs them. When you send a PGP-encrypted message, PGP also creates a digital signature using your private key. The recipient can verify this signature with your public key to confirm that the message came from you and was not tampered with in transit.

The signature is created by hashing the message and encrypting the hash with the sender's private key. The recipient decrypts the signature with the sender's public key, hashes the received message independently, and compares the two hashes. If they match, the message is authentic. This is the same mechanism used in our digital signer tool and explained in our hashing vs encryption guide.

### Component 4: The Web of Trust

The web of trust is PGP's decentralized key verification system. Instead of relying on a central certificate authority (like TLS does), PGP users sign each other's keys to vouch for the mapping between a key and its owner's identity.

If Alice signs Bob's key, she is asserting "I have verified in person that this key belongs to Bob." If Carol trusts Alice's assertions, she can trust Bob's key even without meeting Bob. This creates a graph of trust relationships that allows verification without central authority.

The web of trust is both PGP's greatest innovation and its greatest practical weakness. It is mathematically elegant but socially impractical — most people never attend key signing parties, and maintaining a verified web of trust requires effort that few users are willing to invest.

PGP vs GPG vs OpenPGP

These three terms are often used interchangeably, but they refer to different things:

| Term | What It Is | | --- | --- | | PGP | The original software created by Phil Zimmermann, now a commercial product owned by Broadcom/Symantec | | OpenPGP | The IETF standard (RFC 4880, updated by RFC 9580) that defines the message format and protocol | | GPG (GnuPG) | A free, open-source implementation of the OpenPGP standard, maintained by Werner Koch |

All three are interoperable. A key generated by GPG can decrypt a message encrypted by PGP, and vice versa. For most practical purposes, "PGP" and "GPG" refer to the same thing: OpenPGP-compatible encryption.

Is PGP Still Relevant in 2026

PGP has lost ground in consumer messaging. Signal, WhatsApp, and other apps use the Signal Protocol, which provides end-to-end encryption with a much smoother user experience than PGP ever achieved. For end-to-end encrypted messaging, PGP is no longer the best choice for everyday communication.

But PGP remains important in several specific contexts:

Software signing. Linux package managers (APT, RPM, Pacman) use GPG to verify package integrity. When you install a package on Ubuntu, apt verifies the GPG signature against the distribution's signed keys. This prevents tampered packages from being installed.

Email encryption. For users who need encrypted email — journalists, lawyers, activists, researchers — PGP remains the standard. While S/MIME offers an alternative, it requires a certificate authority and is less flexible. PGP email encryption works with any email provider.

Key verification. Software projects publish PGP keys so users can verify that releases come from the legitimate maintainer. The Tor Project, Qubes OS, and many security tools publish PGP keys for release verification.

Secure code review. Developers use PGP to sign commits and tags in Git. GitHub and GitLab display "Verified" badges for commits signed with a registered GPG key.

Why PGP Is Hard to Use

PGP has a well-deserved reputation for being difficult. The reasons are structural:

Key management is manual. You must generate keys, manage expiration, publish to key servers, and sign (or be signed by) other users. There is no equivalent of a certificate authority doing this automatically.

The tooling is developer-oriented. GPG's command-line interface is powerful but intimidating. Graphical clients exist (Gpg4win, GPG Suite, Kleopatra) but are not as polished as modern messaging apps.

The threat model is complex. PGP does not protect metadata — the subject line, sender, recipient, and timestamp of an encrypted email are all visible. PGP does not provide forward secrecy — if your private key is compromised, all messages encrypted to that key can be decrypted. Signal addresses both of these; PGP does not.

Key discovery is unreliable. Key servers have been abused to publish fake keys, and there is no built-in mechanism to verify a key belongs to the claimed identity without out-of-band verification.

PGP Without Installing Anything

You do not need to install GPG or buy PGP to use OpenPGP encryption. NovelCrypt provides browser-based tools that handle the cryptographic operations client-side, with no server processing and no installation required.

To encrypt a message using PGP's hybrid approach, you can combine NovelCrypt tools:

1. Generate an RSA key pair using the RSA encrypt/decrypt tool. This gives you a public key (to share) and a private key (to keep secret). 2. Generate a random AES key or passphrase and use the AES text encryptor to encrypt your message. This is the symmetric component. 3. Encrypt the AES key with the recipient's RSA public key using the RSA tool. This is the asymmetric key wrapping component. 4. Send the encrypted message and the encrypted AES key together. The recipient decrypts the AES key with their RSA private key, then decrypts the message with the AES key.

To create and verify a digital signature, use the digital signer tool to sign the message with your private key, and the recipient can use the hash verifier to confirm integrity.

For encrypting files rather than text messages, the file encryptor uses AES-256-GCM to encrypt any file type in your browser.

PGP vs RSA: What People Actually Mean

When people ask "PGP vs RSA," they are usually comparing two different categories. PGP is a complete cryptographic system. RSA is a single algorithm. PGP uses RSA (or ECC) as one of its components. The comparison is like asking "cars vs engines" — a car contains an engine, but they are not alternatives to each other.

If the question is "should I use PGP or just use RSA directly," the answer depends on your needs. PGP handles key management, signature creation, key wrapping, and message packaging in a standardized, interoperable format. Using RSA directly means you handle all of those pieces yourself, which increases the risk of implementation errors.

The Bottom Line

PGP is not obsolete, but it is no longer the default for consumer encrypted communication. It remains essential for software signing, email encryption, and key verification in developer and security communities. Its hybrid encryption design — combining symmetric and asymmetric encryption with digital signatures — is the same pattern that powers TLS, Signal, and every modern secure system. Understanding PGP means understanding the architecture that all practical cryptography is built on.

Frequently Asked Questions

Is PGP still used today?

Yes. PGP and its open-source implementation GnuPG (GPG) are still used for software package signing (Linux distributions, package managers), encrypted email, secure code review, key verification for software releases, and journalist-source communication. While PGP has lost ground in consumer messaging to Signal and similar apps, it remains important in developer and security communities.

Is PGP free?

The PGP standard (OpenPGP, defined in RFC 4880 and RFC 9580) is free and open. GnuPG (GPG) is a free, open-source implementation. Commercial PGP products exist (from Symantec/Broadcom), but you do not need to pay for PGP — GPG and browser-based tools provide full PGP functionality at no cost.

Can PGP be cracked?

PGP itself uses strong algorithms (AES, RSA, ECC) that are not practically breakable. However, PGP can be compromised through weak key passphrases, key substitution attacks, implementation bugs, or endpoint compromise. The cryptography is sound; the vulnerabilities are in key management, user behavior, and software implementations.

What is the difference between PGP and GPG?

PGP is the original software and protocol created by Phil Zimmermann in 1991. GPG (GnuPG) is a free, open-source implementation of the OpenPGP standard. They are interoperable — a key generated by GPG can be used by PGP and vice versa. OpenPGP (RFC 4880, updated by RFC 9580) is the IETF standard that both implement.

Try NovelCrypt Tools

Experience military-grade encryption for your sensitive data. Create self-destructing messages, encrypt files, or explore our experimental lab tools.

Explore NovelCrypt