Using second keyring may be misleading?

David Shaw dshaw at jabberwocky.com
Fri Jun 22 14:24:39 CEST 2012


On Jun 21, 2012, at 11:57 PM, Daniel Kahn Gillmor wrote:

> On 06/15/2012 08:30 AM, Georgi Guninski wrote:
>> This is ubuntu's problem I don't care much about, but they need to
>> verify the keys are signed.
>> 
>> The k at k contains a subkey colliding with ubuntu's key 3F272F5B.
> 
> colliding at how many trailing bits?  what happens if you use
> "--keyid-format long"?

It collides in all 64 bits.  It's a v3 subkey on a v4 key, so presumably uses the standard DEADBEEF trick.

David




More information about the Gnupg-devel mailing list