Re: GD doesn't always accept revocations
Jason Harris <[email protected]> Wed, 9 Feb 2005 17:38:46 -0500
| Newsgroups | gmane.comp.encryption.pgp.keyserver-folk,gmane.comp.gnu.gnupg.users |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Feb 09, 2005 at 04:25:48PM -0500, David Shaw wrote: > On Wed, Feb 09, 2005 at 04:14:51PM -0500, Jason Harris wrote: > > It needs only to verify the revocation and remove the key immediately. > > Well, that's one possible answer. Why don't you suggest it to the GD > people? If this isn't already self-evident to them... > Why go through a lot of bother to find an expired or revoked key which > you then manipulate into being acceptable? Just make a brand new key > with your victim's email address and submit that. It's the same > result. For one thing, anyone who followed the GD FAQ and simply removed a key from the GD without revoking it in their own keyring may be duped into confirming the fingerprint of a key they once used and probably still have. The key may or may not be expired, but their encryption client definitely can't heed a revocation that was never generated. For another, why waste good bytes out of /dev/random? Besides, the game is mostly over if the victim must first import a totally unknown key. -- Jason Harris | NIC: JH329, PGP: This _is_ PGP-signed, isn't it? [email protected] _|_ web: http://keyserver.kjsl.com/~jharris/ Got photons? (TM), (C) 2004 _______________________________________________ pgp-keyserver-folk mailing list [email protected] http://lists.kjsl.com/mailman/listinfo/pgp-keyserver-folk
signature.asc
(application/pgp-signature, 309 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (FreeBSD) iJoEARECAFoFAkIKkPZTGGh0dHA6Ly9rZXlzZXJ2ZXIua2pzbC5jb206ODAvcGtz L2xvb2t1cD9vcD1nZXQmc2VhcmNoPTB4RDM5REEwRTMmd2VoYXZleW91bm93PXRy dWUACgkQSypIl9OdoOMjhwCfY6SX4GCzwct4l8CZ9z9GuDaxBWAAn1QHdkb3+MMB 8Typf96gyY63/cPu =Ew1p -----END PGP SIGNATURE-----