Also: let me be clear. “I can fully decrypt your encrypted PGP emails with almost no user interaction” is not FUD. If you doubt the vuln exists, say so. But don’t say it’s not extremely serious for a crypto vuln.
The fact that *I* needed to go around asking some people for info and digging for commits and bugs and mailing list threads to figure out how the fuck this all works and that nobody else did so tells me this disclosure was a massive clusterfuck, and that's on the researchers.
-
-
The researchers notified every single relevant project. What precisely are you asking them to do differently? They gave months of notice on a handful of bugs with a SIMPLE PATCH.
-
If your point is that the PGP client community can’t handle a simple bugfix without having their hands held, then yes, I agree.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.