- cross-posted to:
- lobsters
- cross-posted to:
- lobsters
A talk from the hacker conference 39C3 about security vulnerabilities found in GPG (GnuPG) and similar tools.
They showed 14 vulnerabilities (9 of them are 0-days) 🤯.
Their website: https://gpg.fail/
(in English)



At 09:10 - they demonstrate injecting text that does not break signatures - by appending text after manually inserting null terminator.
\nis the posix newline\ris carriage return