Dark Web Talk

Now live! ๐Ÿ” pgpfreak's key server

Started by pgpfreak ยท Dec 21, 2025

#4053
โ†ณ Replying to @Astartes
Hi :) You're absolutely right to highlight this comment /post/b2156b2e2aa2db09d7db#c-17caf65a495700e343. While I didn't myself in this post, I did link it on my original announcement here /post/6c0a28590f28fef4d73a. I've tried to be as transparent as possible about the different issues that have been raised until now and will continue to do so. We even have a (quite dense) thread dedicated to it on /d/pgpfreaks: /post/6981fe2c00ff7acc7262. You're welcome to comment on any aspect on the discussion.

This specific comment from /u/headjanitor was about how Tor can leak DNS requests if it's not "socksified" on Windows and MacOS. This is because of an incorrected issue from 2011. As you can see in the answers and to keep it short, the way we address it is by running an onion-only service. DNS leaks can't happen if there is no DNS in the first place.

There is an handful of other issues to address with OpenPGP key servers. I won't go through each and every one of them. But. The service we're running is built on top of homemade code (some info about it: /post/d24f8aab440a30252763). It has limited functionalities compared to the original SKS design, which proved to be unsafe in 2021 and has been progressively abandoned. I personally addressed most of the HKP risks I've been able to learn about, mostly through heavy anti-spam rules, and removed SKS capabilities altogether. While the current GPG default configuration should be mostly safe against key poisoning, you don't have to connect your ring to our service at all: everything can be done on our no-JS website. What else can I say. Check and discuss the risk assessment, I guess. We try to keep it as safe as it gets :)
#4054
โ†ณ Replying to @pgpfreak
Thank you for the comprehensive response, it is a complex topic and I have seen that you put a lot of effort into your project even before your response, which is highly commendable.

Still, I would love to hear more opinions about this and whether or not it will be used.

Can't stop myself from asking why its called pgpfreak's and not pgpfreaks though?
#4055
โ†ณ Replying to @Astartes
Thanks. I totally understand the need for more discussion on the matter. It's the only way we can assert a new tool to be safe and while you can't really have it without making the announcements first, I'm sure there's plenty of matters we didn't discuss yet. I can think of a couple of them for sure.

The most important of it is that I'm not trying to change how things work around here. I believe we have a (so far missed) opportunity to make the place safer by popularizing the use of certificates, and that one of the reasons we didn't do it yet is because we missed DN-friendly infrastructure (servers) to do so. But. The baseline of the service I'm running is nothing more than a pastebin for PGP keys, as could be tforum or any other market. And I'm not surprised that both the chaotic history of PGP servers and the novelty do create a perfectly sane suspicion.

About the name... Well, as said in the announcement, I'm not a creative worker and pgpfreak's was kind of straightforward :) However. I also think there is something to do with the name. I may be pushing the switch to it soon enough.
#4058
โ†ณ Replying to @pgpfreak
Good work and nice idea.
#4060
โ†ณ Replying to @clovehitch
Thanks man! Glad you like it :)
#4061
โ†ณ Replying to @pgpfreak
Yeah,

simple and intuitive interface, rapid responses, 100% usefulness.

What is not to like?

Happy holidays bro!
โ˜…

Members-only continuation

This discussion contains more posts.

Create an account or sign in to continue reading the full conversation. 4 additional posts await inside.

Create an accountSign in