modem_down@thebrainbin.org to cybersecurity@infosec.pub · 10 days agoThe gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026media.ccc.deexternal-linkmessage-square12linkfedilinkarrow-up130arrow-down11file-text
arrow-up129arrow-down1external-linkThe gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026media.ccc.demodem_down@thebrainbin.org to cybersecurity@infosec.pub · 10 days agomessage-square12linkfedilinkfile-text
minus-squareChunderBustickles@piefed.nzlinkfedilinkEnglisharrow-up6·10 days agoPlease bear with my dumb ass. if validating a certificate / signature is risking an RCE, does that essentially make this a planet-wide potential supply chain hack (wherever gnupg is used, at least?)
minus-squareChunderBustickles@piefed.nzlinkfedilinkEnglisharrow-up1·10 days agoFollow up: I suppose the verification could be done in a container?
Please bear with my dumb ass. if validating a certificate / signature is risking an RCE, does that essentially make this a planet-wide potential supply chain hack (wherever gnupg is used, at least?)
Follow up: I suppose the verification could be done in a container?