|
|
Message-ID: <fa5d8b21-114e-4791-928c-a6b0a56ba544@gmail.com> Date: Tue, 30 Dec 2025 15:06:37 -0500 From: Demi Marie Obenour <demiobenour@...il.com> To: oss-security@...ts.openwall.com, Werner Koch <wk@...pg.org>, Jacob Bachmeyer <jcb62281@...il.com> Cc: Solar Designer <solar@...nwall.com>, contact@....fail Subject: Re: safe use of cleartext signatures? On 12/30/25 03:47, Werner Koch wrote: > On Tue, 30 Dec 2025 00:34, Jacob Bachmeyer said: > >> structure, or is this basically an unfixable problem? Could GPG >> perform such validation steps and emit a warning if a clearsigned >> message does not strictly conform? > > It does. The thing here is that you need to known what has been signed. > The only way to do this is to let gpg give you the signed and unescaped) > data (with --output FILE). Actually we have the same problem with MIME > when forwarding a mail. Not all MUAs correctly mark which parts are > signed by which signature. What about for detached signatures? -- Sincerely, Demi Marie Obenour (she/her/hers) Download attachment "OpenPGP_0xB288B55FFF9C22C1.asc" of type "application/pgp-keys" (7141 bytes) Download attachment "OpenPGP_signature.asc" of type "application/pgp-signature" (834 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.