Skip to content

The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37]

7.4 relevance
Score Breakdown
technical depth
9
novelty
9
actionability
4
community
8
strategic
7
personal
6

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Deep security postmortem on GPG vulnerabilities, high technical depth and important for infrastructure/security awareness.

AI/ML media.ccc.de
The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37]
Summary

In a 2026 follow-up talk at MRMCD, researcher Lexi Groves details how multiple GPG vulnerabilities she disclosed in 2025 remain unpatched, including a signature-spoofing flaw the maintainer declared 'harmful' rather than fixing. Memory corruption in the basic PGP message parser was addressed, but core footguns persist—demonstrated live without zero-days. The talk critiques responsible disclosure breakdowns with Werner Koch and explores AI/LLM implications for security research, concluding neither researchers nor users are doomed.