Re: Key search interface and email address harvesting

Jason Harris <[email protected]> Mon, 7 Feb 2005 12:33:15 -0500
Newsgroups gmane.comp.encryption.pgp.keyserver-folk
Message-ID <[email protected]>
On Mon, Feb 07, 2005 at 03:40:36PM +0100, Reimer Karlsen-Masur, DFN-CERT wrote:

> I got some request to (sort of) restrict the (SKS) PGP keysearch http
> frontend to only return keys if e.g. the emailaddress search string was an
> exact match of one of the emailaddresses in one of the user IDs in the to be
> returned PGP key.

https://keyserver-beta.pgp.com already does this, so users should
relegate keys there if they need safekeeping.

> Obviously these kinds of restrictions are not sufficient since a potential
> harvester could just go and brute force the keyid name space to retrieve the
> keys by keyid and extract the mailaddresses from the keys. Or a harvester
> could go and download a keydump.... Or a disguised harvester could setup his
> own keyserver and requests syncing...or...

Exactly.

-- 
Jason Harris           |  NIC:  JH329, PGP:  This _is_ PGP-signed, isn't it?
[email protected] _|_ web:  http://keyserver.kjsl.com/~jharris/
          Got photons?   (TM), (C) 2004

_______________________________________________
pgp-keyserver-folk mailing list
[email protected]
http://lists.kjsl.com/mailman/listinfo/pgp-keyserver-folk
signature.asc (application/pgp-signature, 309 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (FreeBSD)

iJoEARECAFoFAkIHpltTGGh0dHA6Ly9rZXlzZXJ2ZXIua2pzbC5jb206ODAvcGtz
L2xvb2t1cD9vcD1nZXQmc2VhcmNoPTB4RDM5REEwRTMmd2VoYXZleW91bm93PXRy
dWUACgkQSypIl9OdoOOP5ACeNF9aNk+/IE+mO2Nfdi6Quath0VIAn0s7/7BEtRfU
juAXfCkO5udV24/Z
=53tJ
-----END PGP SIGNATURE-----