E-Ink News Daily

Back to list

The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37]

The speaker disclosed multiple vulnerabilities in GPG, including memory corruption in the PGP message parser, at 39c3 in December 2025. While some bugs were patched, key issues remain unaddressed, with the main developer opting to declare certain features harmful via a blog post instead of fixing code. The talk also presents novel vulnerabilities and demonstrates live the real-world impact of these unresolved footguns.

Background

GnuPG (GPG) is the most widely used PGP implementation for email encryption and digital signatures. The 39c3 conference took place in December 2025 in Berlin.

Source
Lobsters
Published
Sep 13, 2026 at 01:24 AM
Score
7.0 / 10