Key search interface and email address harvesting
"Reimer Karlsen-Masur, DFN-CERT" <[email protected]> Mon, 07 Feb 2005 15:40:36 +0100
| Newsgroups | gmane.comp.encryption.pgp.keyserver-folk |
|---|---|
| Organization | DFN-CERT Services GmbH |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hi List, I got some request to (sort of) restrict the (SKS) PGP keysearch http frontend to only return keys if e.g. the emailaddress search string was an exact match of one of the emailaddresses in one of the user IDs in the to be returned PGP key. Is there some easy way to get SKS to only return exact matches on user ID mailaddress or (if an UserID has no mailaddress) exact matches of the complete user ID? I know this does not solve the problem but at least raises the bar a bit higher. The reason behind this is that obviously some spammer harvested an emailaddress from a PGP keyserver. Since this email address was specifically created as a bait for keyserver mailaddress harvester it seems that spammers are crawling through (the wildcard) search of PGP keyserver. Obviously these kinds of restrictions are not sufficient since a potential harvester could just go and brute force the keyid name space to retrieve the keys by keyid and extract the mailaddresses from the keys. Or a harvester could go and download a keydump.... Or a disguised harvester could setup his own keyserver and requests syncing...or... Which then brings to mind other techniques to prevent automatic bulk downloading like the request to enter some on-the-fly generated code displayed as image in various OCR resistant fonts... This again would break user-clients like gpg (or their frontends) to retrieve PGP keys automagically for the user. :( Makes public PGP keyservers sort of pointless or at least cripples them or makes them unsynced islands. I would like to hear from you how you are dealing with this kind of threat? And there are other data and privacy protection issues related to running pgp keyservers as well... Any view on this is more than welcome, thanks Reimer - -- Dipl. Inform. Reimer Karlsen-Masur (PKI Team), DFN-CERT Services GmbH https://www.dfn-cert.de, +49 40 808077-615 / +49 40 808077-555 (Hotline) PGP RSA/2048, 1A9E4B95, A6 9E 4F AF F6 C7 2C B8 DA 72 F4 5E B4 A4 F0 66 12. DFN-CERT Workshop und Tutorien, CCH Hamburg, 2-3. Maerz 2005 Infos/Anmeldung unter: https://www.dfn-cert.de/events/ws/2005/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iQEVAwUBQgd93RKWILoankuVAQFdgwf/Tu9AMfKYUYGpZYkpXUYCZjy0WQV74YeI MoWQXw5mdynNPcIHEJePocHADpid6UCTSqOBUQktuA9pHwYU0UFfddtX3PESRTdk s+1VFxjilghlr2711Ge08Ui4tZJ9ky4Sd6w/qjsn63whvftl4D4LBhVoZwnUhWi8 2/gbpLuIdo9yygzDCoLDw54KPaJBrHerbNibtdh0hlmTlOdrHBJjZf2e64VtVe9x fB9I7pdG8kFrJf9Y38+ruJzsHVIT5rrr+1mFo5UTCHSCH1ieHqsA1H0XJQiMNfUQ uKqX1PRrSrRcRkSZ6pyuxXiYj/wmReTfpnK9T1I7nOrm3922trLQ2g== =OjZj -----END PGP SIGNATURE-----