Somebody out there has taken a big dislike to Robert J. Hansen (‘rjh’) and Daniel Kahn Gillmor (‘dkg’), two well-regarded experts in the specialised world of OpenPGP email encryption. . It’s not known who launched the attacks in late June 2019 (Hansen says he has suspects in mind), but it’s the nature of the campaign against them that has people in this corner of encryption worried – a “poisoning” attack against their personal certificate signatures held on the OpenPGP Synchronizing Key Server (SKS) network. It sounds arcane but the effects of this on the sizeable number of people using implementations of the OpenPGP protocol – GnuPGP, SequoiaPGP, OpenPGP.js – are to varying degrees potentially very serious. The link for this article located at Naked Security is no longer available. . Professionals are encountering a compromising strike on OpenPGP credentials, igniting significant worries for individuals relying on secure email communication.. OpenPGP Threats, Email Security, Certificate Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.