Re: Key search interface and email address harvesting

"Reimer Karlsen-Masur, DFN-CERT" <[email protected]> Tue, 08 Feb 2005 10:05:29 +0100
Newsgroups gmane.comp.encryption.pgp.keyserver-folk
Organization DFN-CERT Services GmbH
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

Seth Alan Woolley wrote:
| On Tue, Feb 08, 2005 at 09:16:43AM +0100, Reimer Karlsen-Masur, DFN-CERT
wrote:
|>Teun Nijssen wrote:
|>| Reimer Karlsen-Masur, DFN-CERT wrote on 2005-02-07 15:40:
|>|> The reason behind this is that obviously some spammer harvested an
|>|> emailaddress from a PGP keyserver. Since this email address was
|>|> specifically created as a bait for keyserver mailaddress harvester
|>|> it seems that spammers are crawling through (the wildcard) search
|>|> of PGP keyserver.
|>...
|>|> I would like to hear from you how you are dealing with this kind of
|>|> threat?
|>|
|>|
|>| not.... The only problem that you are not mentioning is that unless
|>| *all* keyservers implement exact matches, any measure does not work. I
|>| don't see that happening soon....
|>
|>yep, I thought of this one - but forgot to put it explicitly into the mail...
|>
|>On the other hand, it is one of the reason for me to direct these questions
|>to many PGP keyserver operators via the list :-)
...

| How do you know one of the sync servers isn't a spammer's agent?

At the *very* end it boils down that we/you don't.

On the other hand we know many of the names/persons/organisations involved
in operating keyservers for quite some years beeing active in the PGP
(keyserver) community building up good track records. And PGP is all about
trust anyway.

In an *other* world you would go and fund yet another PMA/QA like group for
these sorts of questions...with regular meetings and so on :)

In *this* world I just don't want/hesitate to go there, since a many
keyservers are run by brave individuals keeping the PGP spirit/concept of
concurrent redundant availability of public PGP key data and who might not
be able to fund participating in this type of group...

After all public key data *is* (meant to be) *public*. And it was always
seen as a good thing of the PGP concept to be distributed and shared and
robust against DoS attacks.

BTW: If emailaddress harvesting is a serious concern at the moment there
only seems to be one way: build all PGP keyids without an emailaddress.

Cheers

Reimer
- --
Dipl. Inform. Reimer Karlsen-Masur (PKI Team), DFN-CERT Services GmbH
https://www.dfn-cert.de, +49 40 808077-615 / +49 40 808077-555 (Hotline)
PGP RSA/2048, 1A9E4B95, A6 9E 4F AF F6 C7 2C B8  DA 72 F4 5E B4 A4 F0 66

12. DFN-CERT Workshop und Tutorien, CCH Hamburg, 2-3. Maerz 2005
Infos/Anmeldung unter: https://www.dfn-cert.de/events/ws/2005/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iQEVAwUBQgiA1xKWILoankuVAQElcwf/RIKORHqRouOjTALVdurgkfUSZs286TuV
ZjpHdSdwbNmegL0u4fGf/Jnd3TDScPRBcjC2SXJ4B2knYWqGk7eqLPujCbC0bOpy
JwEd8rB2TzUTLdXKCmjNZXfjs5nHAZOnnt12yRCYKbb69GixXBBtv9JvzYX5GLPd
jWY7xGr2XNEHInaF1s9+xXp5bfkYKdZLgdxkZ76Op2D92JxmTHvdxlZ3dsNeSQ5X
yeMoI1sDR0jEJINe9aZgReA/hcQA2ryG0Afi1xFF22ammKCDrc3vrC7NMxqEABhy
uOm/xyaogDQzAzXz6HPWwcNHrXVLvmbj3IDtYzh/N5hmKpdc0gAlmA==
=gu3T
-----END PGP SIGNATURE-----