Re: Key search interface and email address harvesting

Seth Alan Woolley <[email protected]> Tue, 8 Feb 2005 09:39:48 -0800
Newsgroups gmane.comp.encryption.pgp.keyserver-folk
Message-ID <[email protected]>
On Tue, Feb 08, 2005 at 10:05:29AM +0100, Reimer Karlsen-Masur, DFN-CERT wrote:
> Seth Alan Woolley wrote:
> | On Tue, Feb 08, 2005 at 09:16:43AM +0100, Reimer Karlsen-Masur, DFN-CERT
> wrote:
> |>Teun Nijssen wrote:
> |>| Reimer Karlsen-Masur, DFN-CERT wrote on 2005-02-07 15:40:
> |>|> The reason behind this is that obviously some spammer harvested an
> |>|> emailaddress from a PGP keyserver. Since this email address was
> |>|> specifically created as a bait for keyserver mailaddress harvester
> |>|> it seems that spammers are crawling through (the wildcard) search
> |>|> of PGP keyserver.
> |>...
> |>|> I would like to hear from you how you are dealing with this kind of
> |>|> threat?
> |>|
> |>|
> |>| not.... The only problem that you are not mentioning is that unless
> |>| *all* keyservers implement exact matches, any measure does not work. I
> |>| don't see that happening soon....
> |>
> |>yep, I thought of this one - but forgot to put it explicitly into the mail...
> |>
> |>On the other hand, it is one of the reason for me to direct these questions
> |>to many PGP keyserver operators via the list :-)
> ...
> 
> | How do you know one of the sync servers isn't a spammer's agent?
> 
> At the *very* end it boils down that we/you don't.
> 
> On the other hand we know many of the names/persons/organisations involved
> in operating keyservers for quite some years beeing active in the PGP
> (keyserver) community building up good track records. And PGP is all about
> trust anyway.
> 
> In an *other* world you would go and fund yet another PMA/QA like group for
> these sorts of questions...with regular meetings and so on :)
> 
> In *this* world I just don't want/hesitate to go there, since a many
> keyservers are run by brave individuals keeping the PGP spirit/concept of
> concurrent redundant availability of public PGP key data and who might not
> be able to fund participating in this type of group...
> 
> After all public key data *is* (meant to be) *public*. And it was always
> seen as a good thing of the PGP concept to be distributed and shared and
> robust against DoS attacks.
> 
> BTW: If emailaddress harvesting is a serious concern at the moment there
> only seems to be one way: build all PGP keyids without an emailaddress.

Agreed.  I hesitated to ask the question, but as I've been a rare poster 
but long lurker on the list, I didn't see much in the way of checking 
the identity of the keyserver operators.  I didn't consider this a 
problem, and still don't consider harvesting emails from it a serious 
problem.  I think it can be mitigated by technical means.

It's conceivable that somebody could simply run an sha-1 hash of their 
email address and ask people to lookup their key that way.  After all, 
that's what one-way hashes were designed for.

Then again, that doesn't prevent a rumplestiltskin-style attack, 
however, the fact that any domain can be found in the keyserver as well 
as username makes email guessing an order of complexity more 
difficult.

The conversion to this system could be done both on the client and the 
server side fairly quickly and at not much cost for a major benefit 
(more people would perhaps be willing to publish their keys publicly if 
they knew it wasn't trivially spammer-friendly).

Seth

-- 
Seth Alan Woolley [seth at positivism.org], SPAM/UCE is unauthorized
Key id EF10E21A = 36AD 8A92 8499 8439 E6A8  3724 D437 AF5D EF10 E21A
Security Team Leader Source Mage GNU/Linux http://www.sourcemage.org

_______________________________________________
pgp-keyserver-folk mailing list
[email protected]
http://lists.kjsl.com/mailman/listinfo/pgp-keyserver-folk
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)

iD8DBQFCCPlkej9tPAC6OvMRApQkAJ47Zl6zkKkB76wcVhbRcWHqcNFVkgCffmAi
4SZhp1zBmbAB+9jyNGgZpZI=
=Ghh/
-----END PGP SIGNATURE-----