Victory by KO: Attacking OpenPGP Using Key Overwriting
Lara Bruseghini, Daniel Huigens, Kenneth G. Paterson
Abstract
We present a set of attacks on the OpenPGP specification and implementations of it which result in full recovery of users' private keys. The attacks exploit the lack of cryptographic binding between the different fields inside an encrypted private key packet, which include the key algorithm identifier, the cleartext public parameters, and the encrypted private parameters. This allows an attacker who can overwrite certain fields in OpenPGP key packets to perform cross-algorithm attacks, causing a user's software to, for example, misinterpret an ECC private key as being a DSA key. It also allows an attacker to replace the legitimate public parameters with adversarially chosen ones, e.g. allowing them to select the DSA group. We refer to this class of attacks as Key Overwriting (KO) attacks. We provide a detailed analysis of the vulnerability of different OpenPGP libraries to KO attacks, showing in particular that in some cases additional key validation steps performed by libraries that should prevent the attacks in fact allow variant attacks. We also assess the applicability of KO attacks in the context of specific OpenPGP-based applications that reflect different threat models. Finally, we explain how KO attacks can be completely prevented (and the need for key validation obsoleted) at the OpenPGP specification level by expanding the existing proposal of using AEAD schemes for key packet protection to have all the security-relevant public fields included as Associated Data. Version (4) Creation Date Key Algorithm (ECDSA) Curve identifier 𝑂 Public point 𝑄 Public fields (fingerprinted)
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 05898811-ea36-4c68-89be-fb4ec3ed8d1cCited by top-tier papers6
- Caveat Implementor! Key Recovery Attacks on MEGAMartin R. Albrecht, Miro Haller, Lenka Mareková, Kenneth G. PatersonEUROCRYPT 2023 · 8 citations
- End-to-End Encrypted Cloud Storage in the Wild: A Broken EcosystemJonas Hofmann, Kien Tuong TruongCCS 2024 · 5 citations
- MFKDF: Multiple Factors Knocked Down FlatMatteo Scarlata, Matilda Backendal, Miro HallerUSENIX Security 2024 · 3 citations
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
Builds on4
- Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration ChannelsDamian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising et al.USENIX Security 2018 · 64 citations
- Prime and Prejudice: Primality Testing Under Adversarial ConditionsMartin R. Albrecht, Jake Massimo, Kenneth G. Paterson, Juraj SomorovskyCCS 2018 · 21 citations
- On the (In)Security of ElGamal in OpenPGPLuca De Feo, Bertram Poettering, Alessandro SorniottiCCS 2021 · 7 citations
- A Performant, Misuse-Resistant API for Primality TestingJake Massimo, Kenneth G. PatersonCCS 2020
Related papers
- Measuring small subgroup attacks against Diffie-HellmanLuke Valenta, David Adrian, Antonio Sanso, Shaanan Cohney et al.NDSS 2017 · 34 citations
- May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519Daniel Genkin, Luke Valenta, Yuval YaromCCS 2017 · 75 citations
- Mitigation of Attacks on Email End-to-End EncryptionJörg Schwenk, Marcus Brinkmann, Damian Poddebniak, Jens Müller et al.CCS 2020 · 10 citations
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 57 citations
- "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in EmailsJens Müller, Marcus Brinkmann, Damian Poddebniak, Hanno Böck et al.USENIX Security 2019 · 34 citations
