Collisions on GPG signatures

I noticed that Full-Disclosure contained son discussion about a way to forge GPG key signatures.

  1. This basically says that we could sign a GPG key and make it look as though it was trusted by Richard Matthew Stallman. ;)
  2. -seclists.org: (Full Disclosure: Potential gpg forging key signatures with collisions netsecu.org/#249) #security
  3. So now we all need to start thinking the way @earthmelon is...
  4. I'll keep you updated...

Did you find this story interesting? Be the first to or comment.

Liked!

webhat/redhat

Amsterdam based Security Consultant and Risk Manager, with a love of Mashups and Folksonomy. (+31646783584)

Total views
15
  • other
    15

Storify

@Storify