Sunday, January 28, 2018

PGP keys: Can accidental exposures be mitigated?

Recently, security researcher Juho Nurminen attempted to contact Adobe via their Product Security Incident Response Team (PSIRT) regarding a security bug he wanted to report. Instead, he stumbled across something much more vulnerable.

It turns out that Adobe not only published their public key on their website, which is used to send encrypted emails, but the corresponding private PGP keys, as well. After being contacted privately by Nurminen, Adobe moved quickly to revoke the key and had it changed.

The risks of having the entire key pair published on the site could have led to phishing, decryption of traffic, impersonation, and spoofed or signed messages from Adobe's PSIRT. This was extremely embarrassing for Adobe; however, their ability to act quickly was their saving grace.

One thing that they did right was putting a passphrase on the certificate because, without it, the Adobe private key is useless to those with malicious intent. This is one step that every organization should take to protect against the accidental release of a certificate or having an attacker gain access to keys and attempt to use them maliciously. Be warned though -- having a passphrase on a certificate for security is only as good as the passphrase it's being secured with, and a weak passphrase increases the probability of it being brute-forced.

Having procedures in place to quickly revoke PGP keys when needed should be part of your organization's incident response plan. This might not be a common occurrence for many people; however, being able to manage certificates in an expedited fashion could not only save your organization, but could also stop those with malicious intent from attempting to impersonate you.

Having procedures in place to quickly revoke PGP keys when needed should be part of your organization's incident response plan.
Acting quickly is extremely important. Luckily, the Adobe private key had limited use -- the certificate was only being used for email communication for the PSIRT, so it wasn't as publically used as some of their other certificates.

As for how the certificate was published in the first place, that's a different issue -- I'd be very curious to know why this certificate was sent in the first place, and who sent it. There should be some type of privileged access in place for these certificates internally, which I'm assuming is a different department from those managing the CMS.

I understand things can accidentally be miscommunicated or published, but there seems to have been a few breakdowns in the communication process for the Adobe private key to have been published to the internet. I'm hoping Adobe was able to learn from the experience, make adjustments and tighten their security.

My article at:


  1. Replies
    1. Great Article Cyber Security Projects projects for cse Networking Security Projects JavaScript Training in Chennai JavaScript Training in Chennai The Angular Training covers a wide range of topics including Components, Angular Directives, Angular Services, Pipes, security fundamentals, Routing, and Angular programmability. The new Angular TRaining will lay the foundation you need to specialise in Single Page Application developer. Angular Training

  2. Just keep write what you are excited about, and the readers will visit your post.
    hp envy 4500 printer driver download

  3. AWS Training in Bangalore - Live Online & Classroom
    myTectra Amazon Web Services (AWS) certification training helps you to gain real time hands on experience on AWS. myTectra offers AWS training in Bangalore using classroom and AWS Online Training globally. AWS Training at myTectra delivered by the experienced professional who has atleast 4 years of relavent AWS experince and overall 8-15 years of IT experience. myTectra Offers AWS Training since 2013 and retained the positions of Top AWS Training Company in Bangalore and India.

    IOT Training in Bangalore - Live Online & Classroom
    IOT Training course observes iot as the platform for networking of different devices on the internet and their inter related communication. Reading data through the sensors and processing it with applications sitting in the cloud and thereafter passing the processed data to generate different kind of output is the motive of the complete curricula. Students are made to understand the type of input devices and communications among the devices in a wireless media.

  4. Attend The Data Analytics Course From ExcelR. Practical Data Analytics Course Sessions With Assured Placement Support From Experienced Faculty. ExcelR Offers The Data Analytics Course.
    ExcelR Data Analytics Course

  5. Great post! I am actually getting ready to across this information, is very helpful my friend. Also great blog here with all of the valuable information you have. Keep up the good work you are doing here. ExcelR Business Analytics Courses

  6. After you buy Instagram followers australia, you will see that it is a lot simpler to make yourself understood. That is on the grounds that these auto devotees Instagram offer you an undeniable degree of believability. Thus, whatever you say will be viewed as significant and valid. These days, buyers search for mainstream marks that they have caught wind of or that have a rich presence on the web. Because of the way that your business has not been available that long to profit with the reputation that it merits, you should simply pursue a faster route.

  7. Thanks for your sharing great article, I am very happy to read this article and I like it very much!I would also recommend it to my friends.
    sun news live
    sun news
    sun tv live
    news 7 live
    sun news live today
    sun tv news
    sun tv news live
    sun tv live news
    சன் நியூஸ்

  8. Having procedures in place to quickly revoke PGP keys when needed should be part of your organization's incident response plan. This might not be a common occurrence for many people; however, being able to manage certificates in an expedited fashion could not only save your organization, but could also stop those with malicious intent from attempting to impersonate you. Microsoft Toolkit

  9. There is no way to get this useful info . Its very fabulous and easy for me to get it from FM WhatsApp. I am very thankful and I appreciate your intelligent work. Awesome!!

  10. The problem with most people who join Instagram is they only use it for fun and never gain any profit, let alone a dollar from it. But I know a secret way of getting followers on Instagram very easily and having real Instagram followers that would follow you back if you have good content to offer them.

  11. Thanks for the detailed article on this topic. I would like to see more such awesome articles from you. Also you can get the new and best features of FMWhatsapp which are coming in 2022-

    FMWhatsapp APK

  12. idigic is the #1 Instagram Marketing Agency in Sydney and Melbourne. We provide high quality, buy instagram likes australia for businesses of all sizes. Our services include but are not limited to:
    We offer a variety of packages that can be tailored to your needs. All you have to do is choose which one you'd like!

  13. ar skins is a laptop skin template
    company that provides customized laptop skins for the world's leading brands. With more than 20 years in the laptop skin industry, ar skins has an extensive team of designers, who are committed to providing only the best products for their customers.

    Digital Market is a marketplace to sell digital products online easily. It enables sellers to sell digital products quickly and easily. Sellers can upload their digital file, ebook, design or anything else that's digital and within the scope of VectorGi's platform.

  15. The followers surely wish to see your human side too. There are many ways and way to boost your Instagram followers to cultivate your company and spread your ideas, thoughts etc but buy Instagram followers is essential nowadays.

  16. ar skins is the easiest way to customize your laptop with a personalized skin
    . Our design templates are customizable with your own photos and text. We offer skins for laptops, tablets, and even phones. Get started today!

  17. ar skins is a laptop skin template company
    that offers a wide variety of high quality, customizable laptop skins. Customize your laptop with a professional looking skin in minutes and protect your device from scratches and smudges with easy-to-remove adhesive.

  18. VectorGi is a marketplace to sell digital goods online
    easily. Best place to Sell Digital Products quickly. Sell Digital File, Ebook, Software and more with just one click. VectorGi has been created to help you find your customers quickly and easily by providing a way for them to discover what you have to offer. VectorGi provides a safe environment for users that want to buy or sell digital products or services in the simplest way possible!

  19. VectorGi Digital Market is a marketplace to sell digital products online
    easily. It offers a quick and easy way to sell digital goods like eBooks, images, music, or software. With the help of VectorGi's simple sign-up process, sellers can start selling their digital products by uploading them directly to the marketplace. The marketplace offers up payment options such as PayPal and credit card transactions.

  20. First of all, thank you for letting me see this information. I think this article can give me a lot of inspiration. I would appreciate 바카라사이트 if you could post more good contents in the future.

  21. idigic Au is the world’s first music streaming platform that works with SoundCloud. With idigic Au, you can listen to and download your favorite artists without having to leave your comfort zone. idigic Au is the perfect way to stay connected with your favorite music, whether you’re at home or on the soundcloud downloads

  22. FMWhatsApp APK is a modified version of the original Whatsapp with lots of new user experiences. The original WhatsApp contains no bugs, but lack of some features, it becomes useful to use the app.

  23. 스포츠토토

    This is my first time pay a quick visit at here and i am truly happy to read all at alone place.

  24. 스포츠중계

    Thanks for the post and effort! Please keep sharing more such blog.

  25. ar Skin is an easy to use skin for mobile skin template
    that lets you change the look and feel of your device. It's compatible with all Android and iOS devices, including Samsung, Xiaomi, Apple, Vivo, Realme, MacBook, Lenovo and more! With hundreds of thousands of downloads from users around the world, it's time to make your device even more personal.

  26. Vectorgi offers mobile skins for all the latest smartphones and tablets. With over 200 templates, Vectorgi is the world's largest mobile skin theme provider. The company is headquartered in Seoul, South Korea and has offices in Taipei, Taiwan and Guangzhou, China.more@vectorgimobile skin template

  27. iPhone Skin Cut Template Vector
    is a vector graphic of an iPhone skin cut. This design was created to help you create a perfect iPhoneSkinCutTemplate Vector design for your next project.

  28. VectorGi Digital Market is the best place to sell digital goods quickly and easily. We offer a marketplace that allows you to sell digital files, ebooks, and other digital content easily. With VectorGi, you'll have everything you need to quickly and easily sell your products online. From selling digital files to selling ebooks, we have a service that can help you get your products into the market as quickly as possible.WordPress Premium Themes

  29. PS4 Console Cool With Skins
    is one of the most popular gaming consoles in the world. And with good reason. It’s a powerful console that offers a lot of features, including cloud save, remote play, and more. PlayStation 4 is also the perfect platform for new gamers, as it’s easy to learn how to play and gets you into the game quickly. So go ahead and get started on your next gaming adventure today!

  30. Are Skins Enough For Making Gaming Consoles Attractive? Skins can be an extraordinary method for adding an additional a degree of fervor to your gaming console.ps5 skin

  31. Windows 10 Activator apparatus which can be utilized to actuate the Windows. Rather than just initiating Windows, this instrument is additionally ready to enact Microsoft Office. As you realize that there are a ton of different activators accessible on the web, which guarantee that they incorporate no infection. Windows 10 Activator

  32. Thank you so much for sharing this. Would love to see more of these in the future. Keep up the good work! Have you ever tried using FMwhatsApp yet? If not, I would suggest to check it out.