Anrold Reinhold wrote:
>How hard would it be to filter the public key servers for unsigned
>ADKs and either notify the keyowner or just remove the unsigned ADKs?
It might be possible to filter the unsigned ADKs from key servers,
however, it is not clear if the bug discovered is all there is to
worry about. PGP/NAI has not yet given a complete explanation
of how the bug got past quality control for truly reliable security.
Others have noted on the net how long the fault related to
bug has been around, and that despite warnings to PGP
nothing was done about it.
A few have also noted that the pattern of eventual disclosure of
a fault is not unprecedented as a way to discover a built-in
flaw added to gain export approval in an NDA sit-down with
governmental authorities, a process still required by US
export law for strongest crypto and a process that is also in
effect in other countries linked to the US by technology
control pacts such as Wassenaar.
PGP has a wonderful reservoir of goodwill that will surely
help it through this embarassment, but the reservoir has
been drained rather much and needs replenishment.
To help with that Michel Bouissou has circulated a call for
restored confidence in PGP Freeware with a set of
constructive suggestions for PGP/NAI:
http://cryptome.org/pgp-reborn.htm
Are there other suggestions being floated?