Digi-Oek.ch · @DigiOekCH
3 followers · 20 posts · Server social.tchncs.de

(3/3)
Countermeasures for developers/OpenPGP standard: (1) avoid attacks by OpenPGP specification not leaving the task of confirming key to individual . (2) Use an scheme (3). Deprecating encryption option in OpenPGP spec.

Paper & Info: kopenpgp.com/

#ko #KeyOverwritingAttack #verschlüsselung #encryption #e2e #pgp #openpgp #elgamal #aead #implementations #integrity #KOKV

Last updated 2 years ago

Digi-Oek.ch · @DigiOekCH
3 followers · 20 posts · Server social.tchncs.de

Victory by KO: Attacking Using Key Overwriting
pre-print for ACM Conf 11.2022

If you haven't read it yet:

Key Overwriting (KO) attacks might be possible if has write access to the private key of the such as with GopenPGP or OpenPGP.js libraries in applications like ( etc.) and if victim does not inspect their own (!) key before using the key.

#ko #KeyOverwritingAttack #verschlüsselung #encryption #e2e #pgp #fingerprint #gmail #flowcrypt #protonmail #victim #encrypted #adversary #ethz #openpgp

Last updated 2 years ago