Re: Key search interface and email address harvesting
"Reimer Karlsen-Masur, DFN-CERT" <[email protected]> Wed, 09 Feb 2005 12:24:39 +0100
| Newsgroups | gmane.comp.encryption.pgp.keyserver-folk |
|---|---|
| Organization | DFN-CERT Services GmbH |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Seth Alan Woolley wrote: | On Tue, Feb 08, 2005 at 10:05:29AM +0100, Reimer Karlsen-Masur, DFN-CERT wrote: | |>Seth Alan Woolley wrote: |>| On Tue, Feb 08, 2005 at 09:16:43AM +0100, Reimer Karlsen-Masur, DFN-CERT |>wrote: [some points and discussion and concerns about mitigating emailaddress harvesting from pgp keyservers by abusers] | Agreed. I hesitated to ask the question, but as I've been a rare poster | but long lurker on the list, I didn't see much in the way of checking | the identity of the keyserver operators. I didn't consider this a | problem, and still don't consider harvesting emails from it a serious | problem. I think it can be mitigated by technical means. | | It's conceivable that somebody could simply run an sha-1 hash of their | email address and ask people to lookup their key that way. After all, | that's what one-way hashes were designed for. bruteforce the room spanned by the hashvalues. It's larger than just the keyid spanning room :) | Then again, that doesn't prevent a rumplestiltskin-style attack, Sorry what's a 'rumplestiltskin-style attack'? Brute forcing/guessing the hash values? | however, the fact that any domain can be found in the keyserver as well | as username makes email guessing an order of complexity more | difficult. | | The conversion to this system could be done both on the client and the | server side fairly quickly and at not much cost for a major benefit | (more people would perhaps be willing to publish their keys publicly if | they knew it wasn't trivially spammer-friendly). Works only iff all keyservers in the transitive syncing envelope implement it *and* you don't have a lot of legacy (pgp) software trying to retrieve keys the old way. Cheers Reimer - -- Dipl. Inform. Reimer Karlsen-Masur (PKI Team), DFN-CERT Services GmbH https://www.dfn-cert.de, +49 40 808077-615 / +49 40 808077-555 (Hotline) PGP RSA/2048, 1A9E4B95, A6 9E 4F AF F6 C7 2C B8 DA 72 F4 5E B4 A4 F0 66 12. DFN-CERT Workshop und Tutorien, CCH Hamburg, 2-3. Maerz 2005 Infos/Anmeldung unter: https://www.dfn-cert.de/events/ws/2005/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iQEVAwUBQgny9RKWILoankuVAQHzmQgAsl73k5mbYouofbl0uZXrSAG3usphS95A /hGLrMo9OLNrF+xMoxbSK7mSidBYb13Uanho9i/yDUM3/rNjwOZmAXyhTM1vmAIm uL3pT4c5qutcRl1ogkPA7pAMAnLvlgP6ZFGT3LbOGQAWwKHJHNps5FBlGxEb3m8j SNxyF7ws4Z7rwfxzdV8Kq7qfW+C7lLX/Pwp4FA3cQzgJOCSSNZOHEQZS+NkxqDBN bwCQlQz1npOwL4wia4n/j9r6TozLiIr2OOMviC3hbnh/bA2X6f0CJ4dZJY7U9fLk jb3XOJ9B5+tgtQdoeMl/g2y17PTfLyGsaCU6ipUiNlWj7uptZCSiDg== =Z8Vc -----END PGP SIGNATURE-----