Re: GD doesn't always accept revocations

Jason Harris <[email protected]> Wed, 9 Feb 2005 17:38:46 -0500
Newsgroups gmane.comp.encryption.pgp.keyserver-folk,gmane.comp.gnu.gnupg.users
Message-ID <[email protected]>
On Wed, Feb 09, 2005 at 04:25:48PM -0500, David Shaw wrote:
> On Wed, Feb 09, 2005 at 04:14:51PM -0500, Jason Harris wrote:

> > It needs only to verify the revocation and remove the key immediately.
> 
> Well, that's one possible answer.  Why don't you suggest it to the GD
> people?

If this isn't already self-evident to them...

> Why go through a lot of bother to find an expired or revoked key which
> you then manipulate into being acceptable?  Just make a brand new key
> with your victim's email address and submit that.  It's the same
> result.

For one thing, anyone who followed the GD FAQ and simply removed a key
from the GD without revoking it in their own keyring may be duped into
confirming the fingerprint of a key they once used and probably still
have.  The key may or may not be expired, but their encryption client
definitely can't heed a revocation that was never generated.

For another, why waste good bytes out of /dev/random?  Besides, the
game is mostly over if the victim must first import a totally unknown key.

-- 
Jason Harris           |  NIC:  JH329, PGP:  This _is_ PGP-signed, isn't it?
[email protected] _|_ web:  http://keyserver.kjsl.com/~jharris/
          Got photons?   (TM), (C) 2004

_______________________________________________
pgp-keyserver-folk mailing list
[email protected]
http://lists.kjsl.com/mailman/listinfo/pgp-keyserver-folk
signature.asc (application/pgp-signature, 309 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (FreeBSD)

iJoEARECAFoFAkIKkPZTGGh0dHA6Ly9rZXlzZXJ2ZXIua2pzbC5jb206ODAvcGtz
L2xvb2t1cD9vcD1nZXQmc2VhcmNoPTB4RDM5REEwRTMmd2VoYXZleW91bm93PXRy
dWUACgkQSypIl9OdoOMjhwCfY6SX4GCzwct4l8CZ9z9GuDaxBWAAn1QHdkb3+MMB
8Typf96gyY63/cPu
=Ew1p
-----END PGP SIGNATURE-----