• Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms

    Author
    Topic
    #2775748

    “Security researchers are sounding the alarm over a fresh flaw in the JavaScript implementation of OpenPGP (OpenPGP.js) that allows both signed and encrypted messages to be spoofed.

    “Discovered by Codean Labs’ Edoardo Geraci and Thomas Rinsma, the vulnerability essentially undermines the core purpose of using public key cryptography to secure communications.”

    https://www.theregister.com/2025/05/20/openpgp_js_flaw/

    ================

    Make that three Tylenol, please.

    Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
    --
    "The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty

    1 user thanked author for this post.
    Viewing 1 reply thread
    Author
    Replies
    • #2775750

      Read: Don’t use poorly written scripts/ software

    • #2775938

      More clickbait!

      The flaw allows messages to appear as if they are kosher. It does not allow viewing / decrypting existing messages.

      cheers, Paul

      • #2776061

        More clickbait!

        The flaw allows messages to appear as if they are kosher. It does not allow viewing / decrypting existing messages.

        cheers, Paul

        It’s from The Register; they can be somewhat sensationalistic at times; this isn’t one. The PGP vulnerability doesn’t yet have a POC, but it DOES have a CVE number.

        Unless you don’t trust the CVE system any more, then that’s another story.

         

        Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
        --
        "The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty

        1 user thanked author for this post.
        • #2776067

          It’s not a flaw that is going to cause you to lose data / secrets, unless you are targeted by very clever adversary, who knows you use PGP.
          Us mere mortals don’t have to worry.

          cheers, Paul

    Viewing 1 reply thread
    Reply To: Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: