GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 30-Dec-2025 22:17:20 JSTSoatok DreamseekerSoatok Dreamseeker

    We should talk about Werner Koch's response https://gpg.fail on the oss-security mailing list.

    https://www.openwall.com/lists/oss-security/2025/12/29/9

    Yes, and actually the only serious bug from their list.

    Koch either didn't watch the talk, he is in such defense of his own ego that he can't see how serious the bugs were, or he's tacitly admitting that PGP is not a serious recommendation.

    Can you distinguish between these three explanations?

    Could it be all of them are true?

    Impact

    While this may allow remote code execution (RCE), it definitively causes memory corruption.

    Good research.

    I think this sarcastic quip is what reveals Werner Koch's opinion about the security researchers and their work.

    The rest of his email is measured (and partly responding to other mailing list participants rather than the disclosure directly).

    In conversationabout 6 months ago from furry.engineerpermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      https://gpg.fail/
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.