I should have said "any disclosure": EFail was coordinated (6 months notice [1]) and yet GnuPG officially downplayed the risk [2], launched #effail counter-campaign and blamed researchers for bad disclosure [3].
With regards to any of the existing SKS exploits specifically: even if any of them were to undergo coordinated disclosure, it wouldn't have helped: trollwot has been available for 5 years, both keyserver-fs and sks-exploit -- for more than a year. Embargoes don't last that long. All three tools still work.
What GnuPG Project effectively tries to do is to stop people from writing about any security problems period, especially those that are hard to fix.
Can confirm, I've reported a similar attack [1], along with a few other vulnerabilities, and also published exploit tools. I ended up getting legal threats from two people that I see frequently posting to sks-devel@ mailing list.
Additionally, Robert (GnuPG maintainer who wrote this Gist) has attacked [2] another person who wrote a proof-of-concept filesystem on top of SKS that was intended to highlight how broken the design is.
I have not seen a single open source community that would treat full disclosure with such contempt.
At this point SKS network continues to run exclusively on community goodwill. This attack seems to be specifically targeted on GnuPG maintainers, if attacker were to deliberately try to break SKS, they would target someone like Linus Torvalds.
Alternatively, there are other published vulnerabilities with exploits that allow to take the whole SKS network down within half an hour, which were published more than a year ago. And yet, those have not been used, so far.
There are not that many phone manufacturers that even allow you to change the trust anchor (which makes any of this even remotely possible). For example, Samsung uses e-fuses to burn in their signing key, rewriting recovery will permanently trip their attestation (Knox); other manufacturers use similar practices. Pixels are one of the only currently available phones with user-controlled trusted boot in mind.
Chain of trust does protect you from evil maid attacks.
And yes, there can be bugs in application layer, but at least half of all CVEs are memory corruption bugs.
These practices do offer a massive reduction in attack surface. You seem to argue it doesn't matter since it doesn't eliminate attack surface completely.
Librem 5 isn't going to be particularly security-focused: no attestation, no trusted boot, most userspace programs are written in memory unsafe languages like C, with no extra effort memory corruption mitigations. Also, Flatpak offers a permission system that's very limited compared to Android.
As a Linux distribution maintainer, I second that. There are not that many packages that still use SCons, but ones that do often require boilerplate and/or patches to honor standard environment variables like CC, CFLAGS, LDFLAGS. Cross-compiling a SCons package is a nightmare.
If you like that SCons uses Python, I'd suggest to try Meson. It does everything right and exposes a subset of Python API: https://mesonbuild.com
This is not a valid DMCA claim, point one doesn't even mention copyright. I sent a counter-claim, then tried to republish the repo. GitLab said me I will only be able to republish in 10 days if I don't receive a response, and also that they might ban me if I try to republish it again without waiting for due process.
I'm not sure what you expect from the developer, to just take it? He doesn't have power in the company because even though he's a 50% shareholder, he's not on the board of directors.
CEO has sent DMCA takedown request on my GitLab repo, which clearly abuses copyright law. To use the mirrored pages, replace "yegortimoshenko.gitlab.io" in URLs with "yegortimoshenko.github.io".
CEO also blocks everyone who supports Daniel on their IRC channel. I've been repeatedly asked to take down these links and documents, and CEO even told me "they would come after me" if not for the fact that I live in Russia. See IRC logs: https://view.matrix.org/room/!VxEwjfmZAypdXzZfUp:matrix.org/
Sales is means, not a goal in and of itself. What you're suggesting is a broken economic model that doesn't honor people that add to the world (i.e. authors).
> Nitpicking is more excusable for women to do. That's ultimately because men talk to others
> exchange important information, while women only talk to others for social negotiation and
> to test the social standing of others.