Nice to see this bit of intellectual honesty. Would be even nicer if they had explained what that means in terms of PGP keys.
Nice to see this bit of intellectual honesty. Would be even nicer if they had explained what that means in terms of PGP keys.
For example, if an attacker gains access to a victim email account, they could send to their contacts a "trusted" key (as explained above) and then use it to send signed documents to the victim's contacts.
This would defeat an adversary "paranoid" enough to check a key signature, but not paranoid enough to obtain a clear explaination/confirmation of why the key changed...
No...
> For example, if an attacker gains access to a victim email account, they could send to their contacts a "trusted" key (as explained above) and then use it to send signed documents to the victim's contacts.
Ok... But in this scenario the attacker has the victim’s new private key, so they don’t need to create a collision (using OP). They can just use the new private key to sign the documents. Right?
Why ?
> in this scenario the attacker has the victim’s new private key
You don't want to keep your private key in cleartext on your email provider servers, do you ?
Thereby turning the signal intelligence problem into a human intelligence problem.
I'm not really knowledgeable about the implementation details of GPG. Mind explaining how this follows?