| Can confirm, I've reported a similar attack [1], along with a few other vulnerabilities, and also published exploit tools. I ended up getting legal threats from two people that I see frequently posting to sks-devel@ mailing list. Additionally, Robert (GnuPG maintainer who wrote this Gist) has attacked [2] another person who wrote a proof-of-concept filesystem on top of SKS that was intended to highlight how broken the design is. I have not seen a single open source community that would treat full disclosure with such contempt. At this point SKS network continues to run exclusively on community goodwill. This attack seems to be specifically targeted on GnuPG maintainers, if attacker were to deliberately try to break SKS, they would target someone like Linus Torvalds. Alternatively, there are other published vulnerabilities with exploits that allow to take the whole SKS network down within half an hour, which were published more than a year ago. And yet, those have not been used, so far. [1]: https://bitbucket.org/skskeyserver/sks-keyserver/issues/57 [2]: https://twitter.com/robertjhansen/status/1017863443356020738 |
I wish they did, as I am hoping for an outcome similar to bitkeeper/git.