A talk from the hacker conference 39C3 about security vulnerabilities found in GPG (GnuPG) and similar tools.
They showed 14 vulnerabilities (9 of them are 0-days) 🤯.
(in English)
Submitted 1 day ago by lemmydividebyzero@reddthat.com to technology@lemmy.world
https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i
A talk from the hacker conference 39C3 about security vulnerabilities found in GPG (GnuPG) and similar tools.
They showed 14 vulnerabilities (9 of them are 0-days) 🤯.
(in English)
“Similar tools” include
age being particularly funny.
ReginaPhalange@lemmy.world 11 hours ago
At 09:10 - they demonstrate injecting text that does not break signatures - by appending text after manually inserting null terminator.
Sasquatch@lemmy.ml 46 minutes ago
\nis the posix newline\ris carriage return