The first paper mentions some 157 PGP keys and some "probably copy-paste errors." Maybe somebody can tell more about it, I wasn't able to evaluate the effects.
The second didn't analyze PGP keys, but otherwise was certainly impressive.
"Based on my research it seems that over a very long time the use of PGP
implementations with deeply
awed random number generation functions was very rare."
Comments
Exactly. The GPG that generated that keypair was obviously not doing what it was supposed to do.
It can be something on the level of the famous Debian patch fiasco.
The worrying thing is that nobody until now published such findings.
The second found p is 21(!?)
Edit: see the new post from agwa, if all the keys with bad properties came the same way it's much less worrying.
https://eprint.iacr.org/2012/064.pdf
https://factorable.net/weakkeys12.extended.pdf
Thanks.
The first paper mentions some 157 PGP keys and some "probably copy-paste errors." Maybe somebody can tell more about it, I wasn't able to evaluate the effects.
The second didn't analyze PGP keys, but otherwise was certainly impressive.
http://shoestringfoundation.org/cgi-bin/blosxom.cgi/2004/07/...
A look at the PGP ecosystem through the key server data
https://eprint.iacr.org/2015/262.pdf
That one sounds optimistic:
"Based on my research it seems that over a very long time the use of PGP implementations with deeply awed random number generation functions was very rare."