Skip to content

32bit key ids are not secure to use #10

@osminogin

Description

@osminogin

I found examples of the use of 32 bit gpg key ids in the documentation and code. This is a bad behavior, because now it is very easy to generate a colliding 32bit key id with special software.

More information on trouble: https://evil32.com/

In my opinion, a good idea to specify in the documentation that short key ids are no longer safe.

Possible in gpget code is to completely eliminate processing of short ids. This is the current reality.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions