Yet another "GPG bug" that isn't *really* a GPG bug... The app let's you specify a status fd and people pass in "2" and mix it up with stderr? Does *anyone* downstream in the PGP ecosystem understand basic security hygiene? https://neopg.io/blog/gpg-signature-spoof/#proof-of-concept-ii-signature-and-encryption-spoof-enigmail …
-
-
totally agree, but it should be relatively trivial to protect against mis-use like shown here
-
Yes, and the spoofing for human consumption *is* a bug in gpg (they should not be allowing arbitrary terminal control characters printed as filenames).
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
urgh... This is also horrific... my terminal is not (ever?) white... perhaps GPG should encode newlines in the output, or ban "filenames" with `\ngpg:` in them.