logoalt Hacker News

rurbanyesterday at 6:06 PM2 repliesview on HN

They presented critical parser flaws in all major PGP implementations, not just GNU PGP, also sequoia, minisign and age. But gpg made the worst impression to us. wontfix


Replies

porneltoday at 3:25 AM

Sequoia is mentioned in only one vulnerability for supporting lines much longer than gpg. gpg silently truncates and discards long base64 lines and sequoia does not. So the vulnerability is in ability to feed more data to sequoia which doesn't have the silent data loss of gpg.

In all other cases they only used sequoia as a tool to build data for demonstrating gpg vulnerabilities.

show 1 reply
akerl_yesterday at 7:27 PM

Since when are age or minisign PGP implementations?

show 1 reply