Live data from Hacker News

SKS Keyserver Network Under Attack

gist.github.com

101–110 of 197 posts

Re: SKS Keyserver Network Under Attack

#101
post #99

Earlier quoted context omitted.

> This isn't the first time the GnuPG ecosystem has responded this way to attacks. Hmmmm, I think this is a bit of squeaky wheel situation going on. Remember that the sks keyserver pool is mostly a decentralized group of volunteers running a server as a hobby. So you can have all types of people operating keyservers in the pool. For instance, I've been running a keyserver in the pool for several years. However, I don…

The fact that it is simultaneously a "hobby" and an "attempt to help activists communicate securely" is emblematic of the whole problem here. Either way, the time for Hansen to have warned people about the keyservers was when he first became aware of the vulnerability ("well over a decade" ago), not right after it got exploited on him personally . Everything about this response, from the personal offense he's taken t…

> The fact that it is simultaneously a "hobby" and an "attempt to help activists communicate securely" is emblematic of the whole problem here.

Isn't that the way it usually gets done for most non-profit altruistic efforts, though? If I'm a church and run a soup kitchen for the homeless, the volunteers who come in an prepare meals and serve patrons are probably not going to be trained professional chefs. They are going to be people who just want to help and are volunteering as a hobby to try to do some good.

I'm sure soup kitchens deal with this kind of situation all the time, where you have a volunteer complain about this or that, and then an outsider say that soup kitchen is a shit show. That doesn't mean soup kitchens shouldn't exist. It's just the drama you have to deal with when running a soup kitchen.

Re: SKS Keyserver Network Under Attack

#102
post #94
post #47

Earlier quoted context omitted.

> Any particular reason it's difficult to maintain (other than the lack of popularity of FP in general)? A much bigger issue than the language itself is the overall architecture of the server. It uses Berkeley DB as the main database and only handles one connection at a time. So, if your gossip process starts syncing a huge spam key, you block all front-end web requests (see my issue #61[1]). Also, the keyserver is c…

Here in the comment however a new keyserver is presented: https://keys.openpgp.org/about/news#2019-06-12-launch by dpc_pw and Valodim

I'm a bit confused as to the point you're trying to make. Can you please elaborate?

Re: SKS Keyserver Network Under Attack

#103

Earlier quoted context omitted.

The fact that it is simultaneously a "hobby" and an "attempt to help activists communicate securely" is emblematic of the whole problem here. Either way, the time for Hansen to have warned people about the keyservers was when he first became aware of the vulnerability ("well over a decade" ago), not right after it got exploited on him personally . Everything about this response, from the personal offense he's taken t…

> The fact that it is simultaneously a "hobby" and an "attempt to help activists communicate securely" is emblematic of the whole problem here. Isn't that the way it usually gets done for most non-profit altruistic efforts, though? If I'm a church and run a soup kitchen for the homeless, the volunteers who come in an prepare meals and serve patrons are probably not going to be trained professional chefs. They are goi…

This is the difference between a soup kitchen and a neurosurgery clinic.

Re: SKS Keyserver Network Under Attack

#104
post #76

I'd like to gingerly suggest that this is not the way a project that has deliberately set as its adversaries hostile world governments should respond to a trivial, predictable† vandalism attack. Rather, if they're serious about what they're doing – Hansen, in a related document, talks about the "good advice" he gave to dissidents in Venezuela about using GnuPG – they should thank whoever did this. This attack apparen…

I use GPG quite a bit. I sign my git commits with it, occasionally use it to securely transfer files with people, and appreciate to have everything coupled with my Yubikey. What are reasonable alternatives to this right now? If I’m not using the keyservers, it’s not that bad, right?

This is my reaction as well.

This seems bad, but... what should I do? What's the alternative?

I've seen multiple people say that PGP in general is kind of bad and it would be easy for the tech industry to write a secure alternative if it really wanted to. Cool, but that's not useful right now to ordinary people like me who aren't crypto experts who are trying to decide how we should sign/encrypt messages.

I have no idea what I would use as an alternative to PGP.

Re: SKS Keyserver Network Under Attack

#105

>Any time GnuPG has to deal with such a spammed certificate, GnuPG grinds to a halt. So the SKS software is only a part of the problem. Another part is GnuPG, which is unable to deal with a public key with many signatures attached. GnuPG is written in C (not OCaml) and seems to be well maintained. Looks like fixing it can be an effective mitigation against this attack. Or do I miss something?

Not sure how you could fix an OpenPGP client for this case without changing how the keyservers function.

Re: SKS Keyserver Network Under Attack

#106

Earlier quoted context omitted.

I use GPG quite a bit. I sign my git commits with it, occasionally use it to securely transfer files with people, and appreciate to have everything coupled with my Yubikey. What are reasonable alternatives to this right now? If I’m not using the keyservers, it’s not that bad, right?

This is my reaction as well. This seems bad, but... what should I do? What's the alternative? I've seen multiple people say that PGP in general is kind of bad and it would be easy for the tech industry to write a secure alternative if it really wanted to. Cool, but that's not useful right now to ordinary people like me who aren't crypto experts who are trying to decide how we should sign/encrypt messages. I have no i…

To send messages, use a secure messenger, like Signal or Wire. Don't use PGP.

Re: SKS Keyserver Network Under Attack

#107

Earlier quoted context omitted.

I know the folks behind this and I think they’ve approached it thoughtfully and realistically. It’s using a modern OpenPGP implementation and language (Sequoia, Rust) which is a big win. Despite it being centralised, I’d encourage folks to have a look. On that issue, SKS has become so troublesome to run that the number of peers has steadily decreased to the point where there are only 2 entities running the HKPS (“sec…

Out of curiosity, which is more obscure: OCaml or Rust?

Right? I was reading about this and thinking "hey, maybe technically sound but less well-known languages like OCaml or Rust are not always a good choice".

Re: SKS Keyserver Network Under Attack

#108

Earlier quoted context omitted.

The fact that it is simultaneously a "hobby" and an "attempt to help activists communicate securely" is emblematic of the whole problem here. Either way, the time for Hansen to have warned people about the keyservers was when he first became aware of the vulnerability ("well over a decade" ago), not right after it got exploited on him personally . Everything about this response, from the personal offense he's taken t…

> The fact that it is simultaneously a "hobby" and an "attempt to help activists communicate securely" is emblematic of the whole problem here. Isn't that the way it usually gets done for most non-profit altruistic efforts, though? If I'm a church and run a soup kitchen for the homeless, the volunteers who come in an prepare meals and serve patrons are probably not going to be trained professional chefs. They are goi…

Soup kitchens rarely position themselves as being secure against CIA poisoning attacks.

Re: SKS Keyserver Network Under Attack

#109

Earlier quoted context omitted.

This is my reaction as well. This seems bad, but... what should I do? What's the alternative? I've seen multiple people say that PGP in general is kind of bad and it would be easy for the tech industry to write a secure alternative if it really wanted to. Cool, but that's not useful right now to ordinary people like me who aren't crypto experts who are trying to decide how we should sign/encrypt messages. I have no i…

To send messages, use a secure messenger, like Signal or Wire. Don't use PGP.

Okay, and to sign commits or emails?

To encrypt files?

Re: SKS Keyserver Network Under Attack

#110

Earlier quoted context omitted.

I know the folks behind this and I think they’ve approached it thoughtfully and realistically. It’s using a modern OpenPGP implementation and language (Sequoia, Rust) which is a big win. Despite it being centralised, I’d encourage folks to have a look. On that issue, SKS has become so troublesome to run that the number of peers has steadily decreased to the point where there are only 2 entities running the HKPS (“sec…

Out of curiosity, which is more obscure: OCaml or Rust?

The question is not obscurity, the question is security. And there ocaml wins by miles over rust.
Post reply on HN