Public Certificate Poisoning Can Break Some OpenPGP Implementations

OpenPGP installations can grind to a halt and fail to verify the authenticity of downloaded packages as the keyserver network has been flooded with bogus extra signatures attesting ownership of a certificate. […]