Hackers used a feature of the OpenPGP protocol that has been known for over ten years.
We explain what it's about and why it cannot be closed.
/ Unsplash /
Network problems
In mid-June, unknown parties on a network of cryptographic key servers , built on the OpenPGP protocol. This is an IETF standard (), which is used for encrypting emails and other messages. The SKS network was created thirty years ago for distributing public certificates. Tools such as are connected to it for encrypting data and creating electronic digital signatures.
Hackers compromised the certificates of two maintainers of the GnuPG project — Robert Hansen and Daniel Gillmor. Downloading the corrupted certificate from the server causes GnuPG to crash — the system simply hangs. There are reasons to believe that the attackers will not stop at this, and the number of compromised certificates will only increase. Currently, the scale of the problem remains unknown.
The essence of the attack
Hackers exploited a vulnerability in the OpenPGP protocol. It has been known to the community for decades. Even on GitHub there are corresponding exploits. But so far, no one has taken responsibility for closing the 'hole' (we will talk more about the reasons later).
A couple of collections from our blog on Habr:
According to the OpenPGP specification, anyone can add digital signatures to certificates to confirm their ownership. Moreover, there is no limit to the maximum number of signatures. And this leads to a problem — the SKS network allows up to 150,000 signatures on one certificate, but GnuPG does not support such a number. Thus, when loading a certificate, GnuPG (as well as other OpenPGP implementations) hangs.
Un utilizator — importing the certificate took him about 10 minutes. The certificate had over 54,000 signatures, and its size was 17 MB:
$ gpg --homedir=$PWD --recv C4BC2DDB38CCE96485EBE9C2F20691179038E5C6
gpg: key F20691179038E5C6: 4 semnături duplicate eliminate
gpg: key F20691179038E5C6: 54614 semnături nespecificate din cauza lipsei cheilor
gpg: key F20691179038E5C6: 4 semnături reordonate
gpg: key F20691179038E5C6: cheia publică "Daniel Kahn Gillmor " importată
gpg: nu s-au găsit chei de încredere finale
gpg: Numărul total procesat: 1
gpg: importat: 1
$ ls -lh pubring.gpg
-rw-r--r-- 1 filippo staff 17M 2 Iul 16:30 pubring.gpg
Situația este agravată de faptul că serverele de chei OpenPGP nu elimină informațiile despre certificate. Aceasta s-a făcut pentru a putea verifica lanțul tuturor acțiunilor cu certificatele și pentru a exclude înlocuirea lor. Prin urmare, nu se pot elimina elementele compromise.
De fapt, rețeaua SKS reprezintă un mare „server de fișiere”, pe care oricine dorește poate scrie date. Pentru a ilustra problema, anul trecut un rezident GitHub , care stochează documente în rețeaua serverelor de chei criptografice.
De ce vulnerabilitatea nu a fost închisă
Nu a existat un motiv pentru a închide vulnerabilitatea. Anterior, nu a fost folosită pentru atacuri cibernetice. Deși comunitatea IT dezvoltatorilor SKS și OpenPGP să acorde atenție problemei.
Pentru corectitudine, merită menționat că în iunie au lansat totuși un server de chei experimental . Acesta implementa protecție împotriva unor astfel de tipuri de atacuri. Cu toate acestea, baza sa de date este completată de la zero, iar serverul nu face parte din SKS. Prin urmare, va trece timp până când va putea fi utilizat.

/ Unsplash /
În ceea ce privește bug-ul din sistemul original, repararea lui este împiedicată de un mecanism complex de sincronizare. Rețeaua serverelor de chei a fost inițial scrisă ca un concept de dovedire pentru a proteja teza de doctorat a lui Yaron Minsky. De fapt, a fost ales un limbaj destul de specific, OCaml. Potrivit mantenitorului Robert Hansen, a înțelege codul este dificil, prin urmare, în el se fac doar mici corecturi. Pentru a modifica arhitectura SKS, va trebui să fie rescris de la zero.
În orice caz, în GnuPG nu cred că rețeaua va putea fi vreodată reparată. Într-o postare pe GitHub, dezvoltatorii au scris chiar că nu recomandă lucrul cu serverul de chei SKS. Aceasta este, de fapt, una dintre principalele motive pentru care au inițiat tranziția la noul serviciu keys.openpgp.org. Nu ne rămâne decât să urmărim evoluția ulterioară a evenimentelor.
Câteva materiale din blogul nostru corporativ:
Sursa: habr.com
