• lad@programming.dev
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      16 days ago

      That was what I prefer to read instead, but fine

      Edit: I did watch it, they don’t even tell, because it was in the previous disclosure, so I now need to find and watch that one

      Edit2: and from reading https://gpg.fail/ with original vulnerability descriptions I can’t understand how they did the trick with ISO, is the ISO signed as if it were plaintext and allowed truncated lines? If so, this does look pretty bad both on implementation side and on user side, imo

        • ulterno@programming.dev
          link
          fedilink
          English
          arrow-up
          2
          ·
          11 days ago

          Well they did leave out a lot of important information.

          This site seems pretty good though: https://gpg.fail/
          It has all the given vulnerabilities in text.

          Now just need to read and understand all of them and find out which one explains the above comment and the answer to my question is probably another headache.