The short PGP Public Key ID collision attack began to spread on the Internet.
If you are still using the short PGP Public Key ID (for example, 0x43D3B2CA), it is best to use the long PGP Public Key ID (for example, 0xD8E2F63643D3B2CA) as soon as possible and immediately start to notify others. Recently, many public PGP Public Key servers have collided with a large number of counterfeit public keys, featuring the same short-bit IDs and the same primary public key user IDs (names, email addresses, etc, however, it is not created by the Creator and is generated on July 15, June 16, 2014. Up to now, we have recruited multiple users, including one Debian developer. Among them, some spoofed public keys are also signed by the real public keys, including the famous PGP Global Directory Verification Key. At present, it is unclear why such attacks are targeted, and the public keys that conflict with each other may be used for man-in-the-middle attacks, counterfeit encryption, signed emails, and other dangerous behaviors.
This article permanently updates the link address: