Skip to content

Instantly share code, notes, and snippets.

View rjhansen's full-sized avatar

Robert J. Hansen rjhansen

  • Herndon, Virginia
View GitHub Profile
@rjhansen
rjhansen / keyservers.md
Last active April 14, 2024 12:28
SKS Keyserver Network Under Attack

SKS Keyserver Network Under Attack

This work is released under a Creative Commons Attribution-NoDerivatives 4.0 International License.

Terminological Note

"OpenPGP" refers to the OpenPGP protocol, in much the same way that HTML refers to the protocol that specifies how to write a web page. "GnuPG", "SequoiaPGP", "OpenPGP.js", and others are implementations of the OpenPGP protocol in the same way that Mozilla Firefox, Google Chromium, and Microsoft Edge refer to software packages that process HTML data.

Who am I?

@rjhansen
rjhansen / consequences.md
Last active October 1, 2022 04:28
SKS Keyserver Network Attack: Consequences

SKS Keyserver Network Attack: Consequences

This work is released under a Creative Commons Attribution-NoDerivatives 4.0 International License.

Back in late February, the Internet Freedom Festival put together a roundtable of communications security nerds to help dissidents in Venezuela figure out how to organize and communicate in the face of widespread DNS poisoning. I contributed a brief HOWTO explaining what the Maduro regime was doing and some simple, effective mitigations. At the very top of the HOWTO was a paragraph of security considerations. Chief among them was a caution that this document came with an OpenPGP digital signature: before relying on the information in the document they ought ensure nobody had tampered with it, either to install malware into the PDF or to alter the advice I was giving.

I put this HOWTO out in the wild. I've had four people send me thank-you notes for writing it. I figure that means it's been seen by between fo

### Keybase proof
I hereby claim:
* I am rjhansen on github.
* I am rjh (https://keybase.io/rjh) on keybase.
* I have a public key whose fingerprint is 7D8E C4B8 5B6F EDD6 C10D 3C79 1E7A 94D4 E87F 91D5
To claim this, I am signing this object:
@rjhansen
rjhansen / keybase.md
Last active September 14, 2019 07:48

Keybase proof

I hereby claim:

  • I am rjhansen on github.
  • I am rjh (https://keybase.io/rjh) on keybase.
  • I have a public key ASBqHsFVVGBpEL_ZoZ9jzepXw_z04qZKhwFs_85bkS92Ngo

To claim this, I am signing this object: