▲ 33 ▼ The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 (media.ccc.de) submitted 1 week ago by cm0002@literature.cafe to c/opensource@programming.dev 13 comments fedilink hide all child comments
[–] LodeMike@lemmy.today 3 points 1 week ago (4 children) The video, probably. permalink fedilink source parent hideshow 4 child comments replies: [–] ulterno@programming.dev 1 point 5 days ago (2 children) The above question came to me after watching the video. IDK maybe I just have low IQ. permalink fedilink source parent hideshow 2 child comments replies: [–] LodeMike@lemmy.today 1 point 5 days ago (1 child) Might be slop then. I didn't watch the video. permalink fedilink source parent hideshow 1 child comment replies: [–] ulterno@programming.dev 2 points 5 days ago Well they did leave out a lot of important information. This site seems pretty good though: https://gpg.fail/ It has all the given vulnerabilities in text. Now just need to read and understand all of them and find out which one explains the above comment and the answer to my question is probably another headache. permalink fedilink source parent [–] sukhmel@programming.dev 4 points 1 week ago* (last edited 1 week ago) That was what I prefer to read instead, but fine Edit: I did watch it, they don't even tell, because it was in the previous disclosure, so I now need to find and watch that one Edit2: and from reading https://gpg.fail/ with original vulnerability descriptions I can't understand how they did the trick with ISO, is the ISO signed as if it were plaintext and allowed truncated lines? If so, this does look pretty bad both on implementation side and on user side, imo permalink fedilink source parent
[–] ulterno@programming.dev 1 point 5 days ago (2 children) The above question came to me after watching the video. IDK maybe I just have low IQ. permalink fedilink source parent hideshow 2 child comments replies: [–] LodeMike@lemmy.today 1 point 5 days ago (1 child) Might be slop then. I didn't watch the video. permalink fedilink source parent hideshow 1 child comment replies: [–] ulterno@programming.dev 2 points 5 days ago Well they did leave out a lot of important information. This site seems pretty good though: https://gpg.fail/ It has all the given vulnerabilities in text. Now just need to read and understand all of them and find out which one explains the above comment and the answer to my question is probably another headache. permalink fedilink source parent
[–] LodeMike@lemmy.today 1 point 5 days ago (1 child) Might be slop then. I didn't watch the video. permalink fedilink source parent hideshow 1 child comment replies: [–] ulterno@programming.dev 2 points 5 days ago Well they did leave out a lot of important information. This site seems pretty good though: https://gpg.fail/ It has all the given vulnerabilities in text. Now just need to read and understand all of them and find out which one explains the above comment and the answer to my question is probably another headache. permalink fedilink source parent
[–] ulterno@programming.dev 2 points 5 days ago Well they did leave out a lot of important information. This site seems pretty good though: https://gpg.fail/ It has all the given vulnerabilities in text. Now just need to read and understand all of them and find out which one explains the above comment and the answer to my question is probably another headache. permalink fedilink source parent
[–] sukhmel@programming.dev 4 points 1 week ago* (last edited 1 week ago) That was what I prefer to read instead, but fine Edit: I did watch it, they don't even tell, because it was in the previous disclosure, so I now need to find and watch that one Edit2: and from reading https://gpg.fail/ with original vulnerability descriptions I can't understand how they did the trick with ISO, is the ISO signed as if it were plaintext and allowed truncated lines? If so, this does look pretty bad both on implementation side and on user side, imo permalink fedilink source parent