SKS keyservers being used as piracy sites

yakamo k
1 min readAug 27, 2018

--

I was recently poking around an SKS keyerver dump of over 5million+ pgp keys to see if there's anything fun stored in them, i also wanted to inspect what the recent attacks on the vulnerable keyservers left behind.

Just from a guess at the data i was looking at i think its easy to say that more than 50% of the data is junk from people messing around.

The most interesting is the use of Magent Links in UID’s, i found one old magnet link that did not work, and a small collection of links that appeared to still be active.

I suppose its a pretty clever way to use the keyservers as the data is distributed automatically and cannot be removed. A pirates wet dream!

If your curious about searching through sks keyerver dumps you can use pgpdmp or python-pgpdump. Please let me know if you find anything interesting.

[Related Articles]

  1. OpenSUSE concerned about PGP Keyservers and their illegal content
  2. Are SKS keyservers safe and do we need them
  3. OpenPGP Keyservers Now Store ‘Irremovable’ Torrent Magnet Links

--

--