Re: Fake GPG key attack on a Freenet developer

Matthew Toseland <[email protected]>
Newsgroups gmane.network.freenet.devel
Message-ID <[email protected]>
On 24/09/16 03:45, [email protected] wrote:
> http://www.draketo.de/english/gnupg-attack
>
> This happened at an interesting point in time:
> The financial allocation poll was finished last Sunday and I wanted to publish 
> the results - but the GPG signatures of at least 4 participants were invalid 
> and I luckily was paranoid enough to postpone the publishing because of that.
>
> I had requested the contributors to re-sign the attachments with a detached 
> signature, i.e. not embedded into the mail headers but a plain file attachment 
> instead. I could validate 3 of the original attachments to not be tampered 
> with. So likely the invalid sigs were due to bugs in the mailservers.
>
> Still, I am waiting for one signature of a core developer to be validated and 
> considering this event, I will not publish the results until I have a 
> validation.
> His case is also the most concerning one: The mail with the invalid signature 
> did NOT embed it into the mail headers but shipped it as a file attachment. 
> This should be much less likely to be a mailserver bug, so I'd really rather 
> wait for the participant to find time to give me a new sig. He's aware of it.
>
> As consequences, I would request the following:
>
> - I've seen invalid signatures on devl rather frequently in the past and 
> shrugged it off because the contents were not security-critical discussion and 
> mailservers frequently seem to damage the headers in a way which causes 
> invalid sigs.
> Can any of our server admins reproduce this = is this a bug of our server, not 
> my mail client? I had commented on the mails with invalid sigs at the 
> "Financial allocation poll stage 3" thread.
> If yes, can you please investigate the reason? You could ask the senders of 
> those mails for copies from their "Sent mail" dir and diff against what devl 
> received.
> It would be good to fix this: Invalid signatures happening frequently teaches 
> people to ignore it.
>
> - Anyone who is not signing their mails yet should please start doing so.
> The same applies to Git commits.

I thought these were generally caused by configuration errors, with GPG
getting confused due to the hash algorithm configured in the local
config being different to that in the (older) key?

_______________________________________________
Devl mailing list
[email protected]
https://emu.freenetproject.org/cgi-bin/mailman/listinfo/devl
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJX6AYkAAoJEBzu1zFxXR53LJMP/2D6RZ6AcF0S1EcTSTNu60Dc
uXkMlNeE4aYVfPSqA6OkV0OJSN4dicIH77LxPSMb+ONIj23yDO1eysFHhTVyZzf6
SBYY5Yuv0B6BlClx5x+1L6OO3Kz6kDOQLee3k5p7ZYSrnhjud5w8mwmWzx5vL7iy
7ls1HIm6TOQRyWpIogV8bx3kZLXR2XgitiiWyfKKenTwWmQPMbXYMzzHl5twKL20
5yMNK9ZSIcHBdFyzMwpr1JkoJJWgA0PYf3GzYbwgqyFeEf7qInU6HHjq2rlaGUk3
e7nU9tthAwFAhNeB+QrOtqTxRH81fit37H/kdr+4zz1cSdXfmaNVE00agC7ksTie
oyChxRN8GtPEYiHOrIPYgqpMBPLCQ9uUUpQTY6rmUywhjjv8KFpjnDuSDGbngnyf
OHZKtVYcF55SyskUrndDBEgW5CNS1beTdsCTIhoVq3rshy6bSVE7SFZLXMY/yft4
+g9CysChh9i1n0Bs8Jui3YPAzLYZb8GrSA6zsamWFFTq+E0s8kKfjyznjRNK+giP
2d0BPHoDnsQYQ5OzOLGrW6hTnmB+G6vD6P/8heceAxoPIwFO4V7fynUyExDBPiBP
TQrqDGhHQPVVIAqZmRc9VNtpNL3O1YQ3QKlTm/tSOqf1e5VO0M3/BJx5kATaAmRg
96xJlFWYuU/JAZBMeqAE
=X6rw
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.