This week in Security: Censoring Researchers, The Death of OpenPGP, Dereferencing Nulls, and Zoom is Watching You

Last week the schedule for our weekly security column collided with the Independence Day holiday. The upside is that we get a two-for-one deal this week, as we’re covering two weeks worth of news, and there is a lot to cover!

[Petko Petrov], a security researcher in Bulgaria, was arrested …read more

Continue reading This week in Security: Censoring Researchers, The Death of OpenPGP, Dereferencing Nulls, and Zoom is Watching You

Over Dozen Popular Email Clients Found Vulnerable to Signature Spoofing Attacks

A team of security researchers has discovered several vulnerabilities in various implementations of OpenPGP and S/MIME email signature verification that could allow attackers to spoof signatures on over a dozen of popular email clients.

The affected e… Continue reading Over Dozen Popular Email Clients Found Vulnerable to Signature Spoofing Attacks

Should I use the same OpenPGP keys in certificates used to provision the YubiKey PIV slots?

I know PIV and OpenPGP are separate standards and independent applications in the YubiKey, but for newcomers like me they look very similar with their signing, encryption and authentication keys, use cases, etc.

After settin… Continue reading Should I use the same OpenPGP keys in certificates used to provision the YubiKey PIV slots?