Hacker News new | ask | show | jobs
by agroot12 3239 days ago
It is a security problem for the recipient.

Imagine a dissident / whistle blower / journalistic source using gpg. I could send her a message, signed with a new key, and just wait until her gpg executable contacts my server.

Then I have her IP address, and if I am lucky, I can plant an exploit into the very first request response.

1 comments

I imagine this kind of people do not run with default configuration just as they use Tails and not your regular Ubuntu install. If not they can be traced with even less obvious means, just like PGP comments: http://www.csoonline.com/article/2904395/microsoft-subnet/mi...