• lavember@programming.dev
    link
    fedilink
    arrow-up
    5
    ·
    5 days ago

    For example, one of the first vulnerabilities I found, that was used for the introduction hook in the 39c3 talk, remains unpatched to this day. Instead of being fixed with code, Werner Koch - the main developer of GnuPG - published a blog post declaring the widely-used feature being “harmful”; while they had weeks in advance, they published this on day one of 39c3, not even giving us time to respond.

    what the actual fuck

  • diaphragmwp@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    6 days ago

    Is there another thing to use? At least for the flow(s) of “encrypt, transfer, decrypt” or “sign, transfer, verify” for binary files. BSD licensed, preferably.

    EDIT: minisign was mentioned on the talk… not in the most positive way but would still trust (after they get their shit together of course); however would never trust “age” with what they did

    • modem_down@thebrainbin.org
      link
      fedilink
      arrow-up
      1
      ·
      4 days ago

      however would never trust “age” with what they did

      What happened with age (or its devs?) that made you not trust it?

      • diaphragmwp@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 days ago

        (I actually managed to watch basically the same talk at a different event on the site pgp.fail, whoops)

        For me, I feel like the mistake mentioned was the most dead obvious one. Prefixing a plugin name from the file with a path then literally running the executable named. At the end of the talk, an age dev bought the researchers with stickers on camera.

  • ulterno@programming.dev
    link
    fedilink
    English
    arrow-up
    4
    ·
    7 days ago

    Alright, so just because a plain text signature is along with content, doesn’t mean that the content is signed.
    Then how do you check that the content is signed by the plain-text signature given with it?

    I thought that the signature means that either a whole copy of the text is encrypted or a hash of the text is encrypted using the private key, which would mean that spoofing the sign would require solving complexity equal to either of:

    • Finding another string that gives the same hash
    • Finding the private key and signing a new hash with it

    What am I missing?

          • ulterno@programming.dev
            link
            fedilink
            English
            arrow-up
            2
            ·
            7 hours ago

            Well they did leave out a lot of important information.

            This site seems pretty good though: https://gpg.fail/
            It has all the given vulnerabilities in text.

            Now just need to read and understand all of them and find out which one explains the above comment and the answer to my question is probably another headache.

      • lad@programming.dev
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        5 days ago

        That was what I prefer to read instead, but fine

        Edit: I did watch it, they don’t even tell, because it was in the previous disclosure, so I now need to find and watch that one

        Edit2: and from reading https://gpg.fail/ with original vulnerability descriptions I can’t understand how they did the trick with ISO, is the ISO signed as if it were plaintext and allowed truncated lines? If so, this does look pretty bad both on implementation side and on user side, imo