The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 (mrmcd26)

The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 (mrmcd26)

Author: CCC media team September 12, 2026 Duration: 32:27
In 2025, I found and disclosed a bunch of vulnerabilities in GPG, the most used PGP implementation, and held a talk at 39c3 about it. **Some** of the bugs ended up getting fixed. This talk describes the adventure and aftermath of getting there, shows some novel ones, and talks about the state of security in 2026. May contain zero-days =) Until May 2025, I liked PGP, and the GNU Privacy Guard. I poked at it in my free time a lot. One day, that suddenly changed, when I flew too close to the sun and ended up uncovering a vulnerability that allows you to easily spoof a PGP signature when opened naively with the GPG tool. Fast-forward a couple of months, the one vulnerability turned into several independent ones, up to memory corruption in the basic PGP message parser, affecting almost all PGP-related workflows. I disclosed these a few weeks before 39c3 in December 2025. And while some of the vulnerabilities - like the memory corruption in the message parser - got addressed properly, this was not the case for all of them. For example, one of the first vulnerabilities I found, that was used for the introduction hook in the 39c3 talk, remains unpatched to this day. Instead of being fixed with code, Werner Koch - the main developer of GnuPG - published a blog post declaring the widely-used feature being "harmful"; while they had weeks in advance, they published this on day one of 39c3, not even giving us time to respond. Several disgruntled comments followed, but a good portion of the flaws are still not addressed, as I will demonstrate live in the talk. This specific demonstration will not utilize any zero-day vulnerabilities (those come next); we will be showing how much of an issue the footguns (that they refuse to address) at hand really are. Additionally, I will present a few novel vulnerabilities on GPG. Not quite the bombshells as last time, but some nifty bugs that should never have made it into production in the first place, but to demonstrate the state of the GnuPG codebase. The talk closes with some general commentary about the state of security and responsible disclosure, and touch on the topic of AI/LLMs in security (with some of the gpg.fail vulnerabilities as examples); what this means for security researchers, ordinary people and software developers (spoiler: neither end users nor security researchers are doomed). https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://talks.mrmcd.net/2026/talk/D3V8QJ/

Tune into the Chaos Computer Club-recent events feed for a direct line to the forefront of digital culture and critical technology discourse. Curated by the CCC media team, this podcast channels the raw, insightful atmosphere of Europe's most influential hacker association, bringing you recordings from their major gatherings and community events. Each episode is a deep dive into talks and presentations from the last two years, covering topics from cryptography and privacy rights to hardware hacking, societal impacts of surveillance, and open-source philosophy. You'll hear from researchers, activists, and engineers who are actively shaping our digital future, offering perspectives rarely found in mainstream tech conversations. This isn't a produced show with hosts; it's an archival audio stream of genuine conference sessions, complete with audience questions and the spontaneous energy of the live event. For anyone interested in the technical details and ethical debates at the heart of modern technology, this feed serves as an essential, unfiltered resource. Subscribe to this podcast to keep your finger on the pulse of the Chaos Computer Club's ongoing dialogue, where complex ideas are broken down and the tools for a more empowered digital life are openly discussed.
Author: Episodes: 50

Chaos Computer Club - recent events feed
Podcast Episodes
Overcoming Agile (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 30:17
Sometimes frowned upon, yet often found in practice, with lots of variation from one company to another, the idea of _Agile_ has already gone beyond just software development. With this talk, I want to provide a positive…
DOOM in unbekannten Gefilden (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 15:06
Ein weiterer Fall von "Can it Run DOOM?" mit Hürden. Fehlendes SDK, mangelhaftes Datenblatt und Hardware die etwas mehr Rechenleistung hat als man für den Zweck erwarten würde Ein kleiner Projektbericht dazu wie DOOM auf…
Luftgrenzen überwinden: Messen, filtern, kühlen? (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 48:56
Was ist hier eigentlich in der Luft? Wie bekomme ich das wieder aus der Luft raus? Und wie bekomme ich meine Wohnung kühl? In diesem Talk schauen wir uns an, wie du mit ESP32, Lötkolben, Klebeband, 3D-Drucker und co. die…
Vacuum Deposition Systems And You (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 57:49
So, you wanna make some bathtub transistors at your hackerspace? Then you'll probably need to use a vacuum coating system! These are essential and ubiquitous in semiconductor manufacturing... But how do you get on cheap…
The CRA: A key to a more resilient FOSS ecosystem (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 45:24
With the Cyber Resilience Act FOSS projects are legally on the hook as part of software supply chain ecosystems. In order to address regulatory obligations and foster open collaboration within software supply chain ecosy…
Shenzhen und die Elektronikmärkte (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 1:20:36
Eine Reise durch die Elektronikmärkte von Shenzhen, dem Ort von dem eure AliExpress Pakete mit den Bauteilen kommen. Mit vielen Fotos zeige ich wie die Märkte funktionieren und was man dort Spannendes entdecken kann. Ich…
Alles über die Eurobox (mrmcd26) [not-audio_url] [/not-audio_url]

Duration: 45:39
Wir überwinden den Stapelrand des Kleinladungsträgers und begeben uns auf die Suche nach der Euronorm der Euronormbox. Es geht auch um Geschichte, Erfinder und allerlei mehr oder weniger wissenswertes um das womöglich be…