Re: Key search interface and email address harvesting

"Reimer Karlsen-Masur, DFN-CERT" <[email protected]> Wed, 09 Feb 2005 12:24:39 +0100
Newsgroups gmane.comp.encryption.pgp.keyserver-folk
Organization DFN-CERT Services GmbH
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

Seth Alan Woolley wrote:
| On Tue, Feb 08, 2005 at 10:05:29AM +0100, Reimer Karlsen-Masur, DFN-CERT
wrote:
|
|>Seth Alan Woolley wrote:
|>| On Tue, Feb 08, 2005 at 09:16:43AM +0100, Reimer Karlsen-Masur, DFN-CERT
|>wrote:

[some points and discussion and concerns about mitigating emailaddress
harvesting from pgp keyservers by abusers]

| Agreed.  I hesitated to ask the question, but as I've been a rare poster
| but long lurker on the list, I didn't see much in the way of checking
| the identity of the keyserver operators.  I didn't consider this a
| problem, and still don't consider harvesting emails from it a serious
| problem.  I think it can be mitigated by technical means.
|
| It's conceivable that somebody could simply run an sha-1 hash of their
| email address and ask people to lookup their key that way.  After all,
| that's what one-way hashes were designed for.

bruteforce the room spanned by the hashvalues. It's larger than just the
keyid spanning room :)

| Then again, that doesn't prevent a rumplestiltskin-style attack,

Sorry what's a 'rumplestiltskin-style attack'? Brute forcing/guessing the
hash values?

| however, the fact that any domain can be found in the keyserver as well
| as username makes email guessing an order of complexity more
| difficult.
|
| The conversion to this system could be done both on the client and the
| server side fairly quickly and at not much cost for a major benefit
| (more people would perhaps be willing to publish their keys publicly if
| they knew it wasn't trivially spammer-friendly).

Works only iff all keyservers in the transitive syncing envelope implement
it *and* you don't have a lot of legacy (pgp) software trying to retrieve
keys the old way.

Cheers

Reimer
- --
Dipl. Inform. Reimer Karlsen-Masur (PKI Team), DFN-CERT Services GmbH
https://www.dfn-cert.de, +49 40 808077-615 / +49 40 808077-555 (Hotline)
PGP RSA/2048, 1A9E4B95, A6 9E 4F AF F6 C7 2C B8  DA 72 F4 5E B4 A4 F0 66

12. DFN-CERT Workshop und Tutorien, CCH Hamburg, 2-3. Maerz 2005
Infos/Anmeldung unter: https://www.dfn-cert.de/events/ws/2005/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iQEVAwUBQgny9RKWILoankuVAQHzmQgAsl73k5mbYouofbl0uZXrSAG3usphS95A
/hGLrMo9OLNrF+xMoxbSK7mSidBYb13Uanho9i/yDUM3/rNjwOZmAXyhTM1vmAIm
uL3pT4c5qutcRl1ogkPA7pAMAnLvlgP6ZFGT3LbOGQAWwKHJHNps5FBlGxEb3m8j
SNxyF7ws4Z7rwfxzdV8Kq7qfW+C7lLX/Pwp4FA3cQzgJOCSSNZOHEQZS+NkxqDBN
bwCQlQz1npOwL4wia4n/j9r6TozLiIr2OOMviC3hbnh/bA2X6f0CJ4dZJY7U9fLk
jb3XOJ9B5+tgtQdoeMl/g2y17PTfLyGsaCU6ipUiNlWj7uptZCSiDg==
=Z8Vc
-----END PGP SIGNATURE-----