Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If my network knows that I use PGP to login, they may well accept an (illegitimate) announcement that I'm changing my keys to {attacker-generated.asc}.

Of course, really such a login key should only be able to authenticate, and my network should only accept a proper revocation certificate that would need to have been generated by a different key with the 'Certify' action enabled.

How likely or damaging that is obviously depends a lot on who you are, and probably wouldn't be for many people at all. But I assume that's the sort of thing your parent commenter is alluding to.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: