Earlier quoted context omitted.
> This isn't the first time the GnuPG ecosystem has responded this way to attacks. Hmmmm, I think this is a bit of squeaky wheel situation going on. Remember that the sks keyserver pool is mostly a decentralized group of volunteers running a server as a hobby. So you can have all types of people operating keyservers in the pool. For instance, I've been running a keyserver in the pool for several years. However, I don…
The fact that it is simultaneously a "hobby" and an "attempt to help activists communicate securely" is emblematic of the whole problem here. Either way, the time for Hansen to have warned people about the keyservers was when he first became aware of the vulnerability ("well over a decade" ago), not right after it got exploited on him personally . Everything about this response, from the personal offense he's taken t…
So yes, I get the argument that Hansen should have warned people. But I gotta wonder who else has been aware of this vulnerability for years.
And I wonder how bad this could get. I can purge requests to SKS keyservers from my machines, but what about all the upstream impacts? As I understand it, GnuPG authentication is pervasive. And "ask SKS" may be almost as pervasive.