Re: Key search interface and email address harvesting
"Reimer Karlsen-Masur, DFN-CERT" <[email protected]> Tue, 08 Feb 2005 10:05:29 +0100
| Newsgroups | gmane.comp.encryption.pgp.keyserver-folk |
|---|---|
| Organization | DFN-CERT Services GmbH |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Seth Alan Woolley wrote: | On Tue, Feb 08, 2005 at 09:16:43AM +0100, Reimer Karlsen-Masur, DFN-CERT wrote: |>Teun Nijssen wrote: |>| Reimer Karlsen-Masur, DFN-CERT wrote on 2005-02-07 15:40: |>|> The reason behind this is that obviously some spammer harvested an |>|> emailaddress from a PGP keyserver. Since this email address was |>|> specifically created as a bait for keyserver mailaddress harvester |>|> it seems that spammers are crawling through (the wildcard) search |>|> of PGP keyserver. |>... |>|> I would like to hear from you how you are dealing with this kind of |>|> threat? |>| |>| |>| not.... The only problem that you are not mentioning is that unless |>| *all* keyservers implement exact matches, any measure does not work. I |>| don't see that happening soon.... |> |>yep, I thought of this one - but forgot to put it explicitly into the mail... |> |>On the other hand, it is one of the reason for me to direct these questions |>to many PGP keyserver operators via the list :-) ... | How do you know one of the sync servers isn't a spammer's agent? At the *very* end it boils down that we/you don't. On the other hand we know many of the names/persons/organisations involved in operating keyservers for quite some years beeing active in the PGP (keyserver) community building up good track records. And PGP is all about trust anyway. In an *other* world you would go and fund yet another PMA/QA like group for these sorts of questions...with regular meetings and so on :) In *this* world I just don't want/hesitate to go there, since a many keyservers are run by brave individuals keeping the PGP spirit/concept of concurrent redundant availability of public PGP key data and who might not be able to fund participating in this type of group... After all public key data *is* (meant to be) *public*. And it was always seen as a good thing of the PGP concept to be distributed and shared and robust against DoS attacks. BTW: If emailaddress harvesting is a serious concern at the moment there only seems to be one way: build all PGP keyids without an emailaddress. Cheers Reimer - -- Dipl. Inform. Reimer Karlsen-Masur (PKI Team), DFN-CERT Services GmbH https://www.dfn-cert.de, +49 40 808077-615 / +49 40 808077-555 (Hotline) PGP RSA/2048, 1A9E4B95, A6 9E 4F AF F6 C7 2C B8 DA 72 F4 5E B4 A4 F0 66 12. DFN-CERT Workshop und Tutorien, CCH Hamburg, 2-3. Maerz 2005 Infos/Anmeldung unter: https://www.dfn-cert.de/events/ws/2005/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iQEVAwUBQgiA1xKWILoankuVAQElcwf/RIKORHqRouOjTALVdurgkfUSZs286TuV ZjpHdSdwbNmegL0u4fGf/Jnd3TDScPRBcjC2SXJ4B2knYWqGk7eqLPujCbC0bOpy JwEd8rB2TzUTLdXKCmjNZXfjs5nHAZOnnt12yRCYKbb69GixXBBtv9JvzYX5GLPd jWY7xGr2XNEHInaF1s9+xXp5bfkYKdZLgdxkZ76Op2D92JxmTHvdxlZ3dsNeSQ5X yeMoI1sDR0jEJINe9aZgReA/hcQA2ryG0Afi1xFF22ammKCDrc3vrC7NMxqEABhy uOm/xyaogDQzAzXz6HPWwcNHrXVLvmbj3IDtYzh/N5hmKpdc0gAlmA== =gu3T -----END PGP SIGNATURE-----