We should talk about Werner Koch's response gpg.fail on the oss-security mailing list.

openwall.com/lists/oss-securit

Yes, and actually the only serious bug from their list.

Koch either didn't watch the talk, he is in such defense of his own ego that he can't see how serious the bugs were, or he's tacitly admitting that PGP is not a serious recommendation.

Can you distinguish between these three explanations?

Could it be all of them are true?

Impact

While this may allow remote code execution (RCE), it definitively causes memory corruption.

Good research.

I think this sarcastic quip is what reveals Werner Koch's opinion about the security researchers and their work.

The rest of his email is measured (and partly responding to other mailing list participants rather than the disclosure directly).

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://furry.engineer/users/soatok/statuses/115808706629684451 on your instance and quote it. (Note that quoting is not supported in Mastodon.)