LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Friday, June 3rd, 2016

    Time Event
    12:19a
    [$] LWN.net Weekly Edition for June 3, 2016
    The LWN.net Weekly Edition for June 3, 2016 is available.
    2:23p
    Friday's security updates

    Debian has updated libxml2 (multiple vulnerabilities).

    Mageia has updated chromium-browser-stable (M5: multiple vulnerabilities), libgd (M5: multiple vulnerabilities), nginx (M5: denial of service), pgpdump (M5: buffer overrun), and php (M5: multiple vulnerabilities).

    Red Hat has updated chromium-browser (RHEL6: multiple vulnerabilities).

    Ubuntu has updated nginx (14.04, 15.10, 16.04: denial of service).

    11:12p
    Wolf: Stop it with those short PGP key IDs!

    At his blog, Gunnar Wolf urges developers to stop using "short" (eight hex-digit) PGP key IDs as soon as possible. The impetus for the advice originates with Debian's Enrico Zini, who recently found two keys sharing the same short ID in the wild. The possibility of short-ID collisions has been known for a while, but it is still disconcerting to see in the wild. "Those three keys are not (yet?) uploaded to the keyservers, though... But we can expect them to appear at any point in the future. We don't know who is behind this, or what his purpose is. We just know this looks very evil."

    Wolf goes on to note that short IDs are not merely human-readable conveniences, but are actually used to identify PGP keys in some software programs. To mitigate the risk, he recommends configuring GnuPG to never shows short IDs, to ensure that other programs do not consume short IDs, and to "only sign somebody else's key if you see and verify its full fingerprint. [...] And there are surely many other important recommendations. But this is a good set of points to start with."

    << Previous Day 2016/06/03
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org