[openpgp] Re: Certificate discovery over HKP
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <ywsjaFv5IFyH29E5KNpWJkz3HN2HJG6-YpLDB7kdCrmq7SpjM5m0ufn-bkD6p05nwYMYtw-eiNEO8wdcNqnLI9Xp2CgHlWq7g3D0zvCtNY0=@protonmail.com> |
On Tuesday, April 8th, 2025 at 21:41, Andrew Gallagher wrote: > An MITM could redirect to a malicious keyserver and serve a fake cert with an attacker-controlled encryption subkey. They could even bind the real subkey as a second encryption subkey to make the attack silent. For the recipient, they can make the attack silent also when serving no key, if they can MITM the email as well (which is the only scenario where any of this is a real attack), because they can encrypt the email with the recipient's key before sending it on (and after reading the contents). So the only difference here is that the attack is silent also for the sender, in the sense that they will still see that the message will be encrypted, if they trust the keyserver. Perhaps that's still significant in the sense that they might be more willing to send sensitive data in an encrypted email (but then again, you could argue that in that case they should verify the key first). Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]