We should talk about Werner Koch's response gpg.fail on the oss-security mailing list.

openwall.com/lists/oss-securit…

Yes, and actually the only serious bug from their list.


Koch either didn't watch the talk, he is in such defense of his own ego that he can't see how serious the bugs were, or he's tacitly admitting that PGP is not a serious recommendation.

Can you distinguish between these three explanations?

Could it be all of them are true?

Impact

While this may allow remote code execution (RCE), it definitively causes memory corruption.


Good research.


I think this sarcastic quip is what reveals Werner Koch's opinion about the security researchers and their work.

The rest of his email is measured (and partly responding to other mailing list participants rather than the disclosure directly).

in reply to Soatok Dreamseeker

what I don't get is why you take this opportunity to attack #pgp in general, like taking the opportunity to push for some agenda, the site is called gpg.fail, GPG not PGP, most of the problems are related to gpg or some C code implementation bug, or using gpg and others in the command line and getting tricked by some ansi printing in the terminal, how that translates to "let's kill pgp"? ex. none of the listed problems affect #DeltaChat at all

(I was present in the gpg.fail talk btw)

This entry was edited (1 week ago)
in reply to Soatok Dreamseeker

I think 2026 should be the year that we make PGP irrelevant.

Not just GnuPG (Koch's implementation), but the entire OpenPGP ecosystem.

Most cryptographers I talk to gave up on PGP over a decade ago.

(After seeing the arrogance and dismissiveness that bled through Koch's oss-security email, who can blame them?)

If you're a country whose government mandates the use of PGP, even in obscure places, let's talk about how to replace PGP.

in reply to Soatok Dreamseeker

Why do the failures of gpg imply that openpgp and rfc9580 are bad? Have you looked at modern ways of doing openpgp and email like chatmail.at does it?
See also chaos.social/@delta/1157966260…

There are also many broken ways to implement signal protocols but they are not useful as examples for discrediting signal.


Relax 😎! GPG is not OpenPGP!

Yesterday, vulnerabilities were published gpg.fail but they don't affect #deltachat or other #chatmail clients because

A) We never used #gnupg for anything; we use the modern #rustlang #openpgp implementation @rpgp, security audited multiple times.

B) #openpgp is fine, as modernized in #RFC9580, which already warns against several #gpgfail issues (gpg didn't implement that spec)

Please spread the word that #gpg is not #openpgp ... Thanks! #39c3


This entry was edited (1 week ago)