Re: Key search interface and email address harvesting

Teun Nijssen <[email protected]> Mon, 07 Feb 2005 22:16:30 +0100
Newsgroups gmane.comp.encryption.pgp.keyserver-folk
Organization Tilburg University
Message-ID <[email protected]>
Hi Reimer,

Reimer Karlsen-Masur, DFN-CERT wrote on 2005-02-07 15:40:
> 
> The reason behind this is that obviously some spammer harvested an
> emailaddress from a PGP keyserver. Since this email address was 
> specifically
> created as a bait for keyserver mailaddress harvester it seems that 
> spammers
> are crawling through (the wildcard) search of PGP keyserver.

I've seen a case where a SURFnet customer reported a spamrun with in 
sequence! to: addresses that were precisely the mail addresses of all 
keys from that customer. Yep, the mail addresses are certainly abused.

> Obviously these kinds of restrictions are not sufficient since a potential
> harvester could just go and brute force the keyid name space to retrieve 
> the
> keys by keyid and extract the mailaddresses from the keys. Or a harvester
> could go and download a keydump.... Or a disguised harvester could setup 
> his
> own keyserver and requests syncing...or...

right.

> Which then brings to mind other techniques to prevent automatic bulk
> downloading like the request to enter some on-the-fly generated code
> displayed as image in various OCR resistant fonts...

> I would like to hear from you how you are dealing with this kind of threat?

not.... The only problem that you are not mentioning is that unless 
*all* keyservers implement exact matches, any measure does not work. I 
don't see that happening soon....

cheers,

teun

_______________________________________________
pgp-keyserver-folk mailing list
[email protected]
http://lists.kjsl.com/mailman/listinfo/pgp-keyserver-folk
signature.asc (application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (MingW32)

iD8DBQFCB9qv14y85WanSzERAv3sAJ49hGgszf+YmZTEAMN2f4tOTYDSDwCdG66+
OTADne1aMeGzAkSj3tguYKQ=
=w505
-----END PGP SIGNATURE-----