PGP Key Poisoner

Robert J. Hansen rjh at
Tue Aug 13 05:35:15 CEST 2019

> I don't want to warm-up this topic again, but... didn't Robert said in his
> github gist that the issue was known for more than a decade?

I did.  Much closer to two decades than one.  I remember talking about
it with Randy Harmon of PGP Security in 2000.

> Why was is then not fixed a decade ago, like it was done with 2.2.17?

Re-read my Gist, please.  It's all in there.

