An attacker can put a plaintext in detached signature so that a user might see it by gpg --decrypt.
A user could be deceived (or confused, at least).
Description
Description
Revisions and Commits
Revisions and Commits
| Status | Assigned | Task | ||
|---|---|---|---|---|
| Restricted Maniphest Task | ||||
| Resolved | • werner | T7903 Multiple Plaintext Attack on Detached PGP Signatures in GnuPG |
Event Timeline
Comment Actions
We have fixed it but the commit also states:
But note: Using the output of the verify command for detached
signatures is useless because with a non-manipulated signature nothing
would haven been written.
Comment Actions
Note using the output of --decrypt directly on the tty is a Bad Idea(tm). You won't cat arbitrary files to your tty for the same reason.
BTW, if you watched CitizenFour please don't follow the example given in the first scene where someone types gpg -d on the tty.