Skip to content

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone

We should talk about Werner Koch's response https://gpg.fail on the oss-security mailing list.

Uncategorized
3 2 0
  • We should talk about Werner Koch's response https://gpg.fail on the oss-security mailing list.

    https://www.openwall.com/lists/oss-security/2025/12/29/9

    Yes, and actually the only serious bug from their list.

    Koch either didn't watch the talk, he is in such defense of his own ego that he can't see how serious the bugs were, or he's tacitly admitting that PGP is not a serious recommendation.

    Can you distinguish between these three explanations?

    Could it be all of them are true?

    Impact

    While this may allow remote code execution (RCE), it definitively causes memory corruption.

    Good research.

    I think this sarcastic quip is what reveals Werner Koch's opinion about the security researchers and their work.

    The rest of his email is measured (and partly responding to other mailing list participants rather than the disclosure directly).

  • We should talk about Werner Koch's response https://gpg.fail on the oss-security mailing list.

    https://www.openwall.com/lists/oss-security/2025/12/29/9

    Yes, and actually the only serious bug from their list.

    Koch either didn't watch the talk, he is in such defense of his own ego that he can't see how serious the bugs were, or he's tacitly admitting that PGP is not a serious recommendation.

    Can you distinguish between these three explanations?

    Could it be all of them are true?

    Impact

    While this may allow remote code execution (RCE), it definitively causes memory corruption.

    Good research.

    I think this sarcastic quip is what reveals Werner Koch's opinion about the security researchers and their work.

    The rest of his email is measured (and partly responding to other mailing list participants rather than the disclosure directly).

    I think 2026 should be the year that we make PGP irrelevant.

    Not just GnuPG (Koch's implementation), but the entire OpenPGP ecosystem.

    Most cryptographers I talk to gave up on PGP over a decade ago.

    (After seeing the arrogance and dismissiveness that bled through Koch's oss-security email, who can blame them?)

    If you're a country whose government mandates the use of PGP, even in obscure places, let's talk about how to replace PGP.

  • I think 2026 should be the year that we make PGP irrelevant.

    Not just GnuPG (Koch's implementation), but the entire OpenPGP ecosystem.

    Most cryptographers I talk to gave up on PGP over a decade ago.

    (After seeing the arrogance and dismissiveness that bled through Koch's oss-security email, who can blame them?)

    If you're a country whose government mandates the use of PGP, even in obscure places, let's talk about how to replace PGP.

    @soatok
    Since OS repositories rely on gpg for validating package signatures I took the liberty to forward the talk to my support contact at SUSE. He called me half an hour later stating that he's half through the talk and had already forwarded it to their internal security maillist because it's like a bad car accident you know you shouldn't stare at but you just can't stop watching... and I'm pretty sure Red Hat is watching, too.

  • oblomov@sociale.networkundefined oblomov@sociale.network shared this topic on

Gli ultimi otto messaggi ricevuti dalla Federazione
Post suggeriti
  • 0 Votes
    1 Posts
    0 Views
    Lavoratore muore per il freddo nei cantieri delle olimpiadi a cortina. “lo specchio del lavoro tossico e nocivo dei grandi eventi”@anarchia È morto per il freddo all’età di 55 anni Pietro Zantonini, originario di Brindisi, durante un turno di vigilanza notturna nel cantiere delle olimpiadi Milano-Cortina.
  • 0 Votes
    1 Posts
    0 Views
    La battaglia per la libertà cognitiva nell'era dell'intelligenza artificiale aziendaleLa libertà di pensiero non è solo uno scudo contro le intrusioni, è il terreno su cui costruiamo tutto il resto: il diritto di esprimersi, dissentire, credere, imparare, amare. Richiede sia libertà negative (da manipolazione, sorveglianza, coercizione) sia positive (di immaginare alternative, di cercare la verità, di plasmare le nostre opinioni e preferenze).https://www.techpolicy.press/the-battle-for-cognitive-liberty-in-the-age-of-corporate-ai/@aitech
  • 0 Votes
    1 Posts
    1 Views
    The Gloaming - 2 (2016)La sfida era notevole: riportare la musica folk al centro dell’attenzione del pubblico, con un progetto che non si ponesse limiti strutturali e culturali.E’ il 2011 quando Iarla Ó Lionáird, Martin Hayes, Caoimhin Ó Raghallaigh, Thomas Bartlett e Dennis Cahill, partendo dagli Stati Uniti, intraprendono una tournée con il primo superg... https://noblogo.org/available/the-gloaming-2-2016Segui il blog e ascolta un album al giorno: @available#LaMusicaCiSalva #UnoDisco #DiscoDelGiorno #Spettacoli
  • 0 Votes
    4 Posts
    2 Views
    @macfranc @lauramassera @eticadigitale beh, attenzione perché la Apple deve assolutamente garantire (quasi per contratto) ai suoi clienti la privacy e la protezione dei loro dati. Tanto da avvisare loro stessi diversi clienti che nemmeno si erano accorti di aver subito intrusioni e controlli attivi sui propri dispositivi offrendo persino assistenza legale. Difendono semplicemente il loro "feudo" dando protezione (finché conviene) ai loro protetti che continuano semplicemente a consumare gadget e giochini digitali. Della libertà e della privacy in sé non gliene importa nulla a nessuno, né a chi si lascia possedere né tantomeno alle grandi aziende come Apple.