[openpgp] Re: Certificate discovery over HKP

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <ywsjaFv5IFyH29E5KNpWJkz3HN2HJG6-YpLDB7kdCrmq7SpjM5m0ufn-bkD6p05nwYMYtw-eiNEO8wdcNqnLI9Xp2CgHlWq7g3D0zvCtNY0=@protonmail.com>
On Tuesday, April 8th, 2025 at 21:41, Andrew Gallagher wrote:
> An MITM could redirect to a malicious keyserver and serve a fake cert with an attacker-controlled encryption subkey. They could even bind the real subkey as a second encryption subkey to make the attack silent.

For the recipient, they can make the attack silent also when serving no
key, if they can MITM the email as well (which is the only scenario
where any of this is a real attack), because they can encrypt the email
with the recipient's key before sending it on (and after reading the
contents).

So the only difference here is that the attack is silent also for the
sender, in the sense that they will still see that the message will be
encrypted, if they trust the keyserver. Perhaps that's still significant
in the sense that they might be more willing to send sensitive data in
an encrypted email (but then again, you could argue that in that case
they should verify the key first).

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.