Someone Is Spamming and Breaking a Core Component of PGP's Ecosystem

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12KJaS+F_EjSZHpfTQ5JBGackOSEa7=57J-Mizg2xhgWHQ@mail.gmail.com>
'A new wave of spamming attacks on a core component of PGP's ecosystem
has highlighted a fundamental weakness in the whole ecosystem. From a
report:

Unknown attackers are spamming a core component of the ecosystem of
the well-known encryption software PGP, breaking users' PGP
installations and clients. What's worse, there may be no way to stop
them. Last week, contributors to the PGP protocol GnuPG noticed that
someone was "poisoning" or "flooding" their certificates. In this
case, poisoning refers to an attack where someone spams a certificate
with a large number of signatures or certifications. This makes it
impossible for the the PGP software that people use to verify its
authenticity, which can make the software unusable or break. In
practice, according to one of the GnuPG developers targeted by this
attack, the hackers could make it impossible for people using Linux to
download updates, which are verified via PGP.'

-- source: https://it.slashdot.org/story/19/07/03/2048235

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.