Key search interface and email address harvesting

"Reimer Karlsen-Masur, DFN-CERT" <[email protected]> Mon, 07 Feb 2005 15:40:36 +0100
Newsgroups gmane.comp.encryption.pgp.keyserver-folk
Organization DFN-CERT Services GmbH
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

Hi List,

I got some request to (sort of) restrict the (SKS) PGP keysearch http
frontend to only return keys if e.g. the emailaddress search string was an
exact match of one of the emailaddresses in one of the user IDs in the to be
returned PGP key.

Is there some easy way to get SKS to only return exact matches on user ID
mailaddress or (if an UserID has no mailaddress) exact matches of the
complete user ID? I know this does not solve the problem but at least raises
the bar a bit higher.

The reason behind this is that obviously some spammer harvested an
emailaddress from a PGP keyserver. Since this email address was specifically
created as a bait for keyserver mailaddress harvester it seems that spammers
are crawling through (the wildcard) search of PGP keyserver.

Obviously these kinds of restrictions are not sufficient since a potential
harvester could just go and brute force the keyid name space to retrieve the
keys by keyid and extract the mailaddresses from the keys. Or a harvester
could go and download a keydump.... Or a disguised harvester could setup his
own keyserver and requests syncing...or...

Which then brings to mind other techniques to prevent automatic bulk
downloading like the request to enter some on-the-fly generated code
displayed as image in various OCR resistant fonts...

This again would break user-clients like gpg (or their frontends) to
retrieve PGP keys automagically for the user. :( Makes public PGP keyservers
sort of pointless or at least cripples them or makes them unsynced islands.

I would like to hear from you how you are dealing with this kind of threat?
And there are other data and privacy protection issues related to running
pgp keyservers as well...

Any view on this is more than welcome,

thanks

Reimer
- --
Dipl. Inform. Reimer Karlsen-Masur (PKI Team), DFN-CERT Services GmbH
https://www.dfn-cert.de, +49 40 808077-615 / +49 40 808077-555 (Hotline)
PGP RSA/2048, 1A9E4B95, A6 9E 4F AF F6 C7 2C B8  DA 72 F4 5E B4 A4 F0 66

12. DFN-CERT Workshop und Tutorien, CCH Hamburg, 2-3. Maerz 2005
Infos/Anmeldung unter: https://www.dfn-cert.de/events/ws/2005/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iQEVAwUBQgd93RKWILoankuVAQFdgwf/Tu9AMfKYUYGpZYkpXUYCZjy0WQV74YeI
MoWQXw5mdynNPcIHEJePocHADpid6UCTSqOBUQktuA9pHwYU0UFfddtX3PESRTdk
s+1VFxjilghlr2711Ge08Ui4tZJ9ky4Sd6w/qjsn63whvftl4D4LBhVoZwnUhWi8
2/gbpLuIdo9yygzDCoLDw54KPaJBrHerbNibtdh0hlmTlOdrHBJjZf2e64VtVe9x
fB9I7pdG8kFrJf9Y38+ruJzsHVIT5rrr+1mFo5UTCHSCH1ieHqsA1H0XJQiMNfUQ
uKqX1PRrSrRcRkSZ6pyuxXiYj/wmReTfpnK9T1I7nOrm3922trLQ2g==
=OjZj
-----END PGP SIGNATURE-----