Adobe Accidentally Published Its Private PGP Key in a Big Blunder

Advertisement
By Gadgets 360 Staff | Updated: 25 September 2017 18:48 IST
Highlights
  • Adobe accidentally published its private PGP key in a blog post
  • The mishap was quickly spotted by security researchers
  • Adobe’s mistake serves as a lesson to all of us

 

Last week Adobe accidentally published its private and public PGP keys, in what has quickly been pronounced as one of the silliest yet critical mistakes done by a company of Adobe's size. Alert security researchers were quick to spot Adobe's mishap. The company has since taken down the key from its website and issued a new public key.

The incident happened last week when Adobe's product security incident response team (PSIRT) published the private PGP key in a blog post. Adobe was quick to resolve its mistake, but security researchers worldwide were able to quickly spot what was amiss. Archived version of the original post is still available online.

Advertisement

Pretty Good Privacy, or PGP, is a system that allows encrypted emails to be sent and received over the Internet, with only the concerned party holding the keys to the encryption. By disclosing the private PGP key, Adobe unwittingly allowed anyone to decode their emails and pretend to be from Adobe's incident response team.

Advertisement

Security firm Sophos noted that it was unlikely anyone could have misused their private PGP key. "Fortunately, as far as we can see, Adobe's (now-revoked) private key was itself encrypted with a passphrase, meaning that it can't be used without a secret unlock code of its own, but private keys aren't supposed to be revealed even if they are stored in encrypted form," Paul Ducklin, a security researcher at Sophos wrote in a blog post.

As plenty of people united to make fun of Adobe's mistake, some used the opportunity to explain why the mistake happened and its implications for us all of those who use encrypted emails. "Some blame should go on the email client software or PGP key software that allowed user to 'accidentally' export the wrong key," Otto Kekalainen, CEO of Seravo.com wrote on Twitter. "PGP/GPG tools are not exactly designed by usability experts. For good security, usability matters. How to attract UX designers here?"

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: adobe, pgp, pgp key, security, privacy, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  2. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  3. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  4. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  5. Flipkart Buy Buy 2025 Sale With Discounts on iPhone 16 Begins on This Date
  6. Samsung May Limit Exynos 2600 to South Korea's Galaxy S26 Units
  7. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  8. Apple Announces App Store Awards 2025 Winners: Check List
  9. Realme Watch 5 Launched in India With Up to 16-Day Battery Life: See Price
  1. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  2. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  3. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  4. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  5. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  6. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
  7. Samsung Galaxy S26 Series May Get Exynos 2600 Chipset Exclusively in South Korea: Report
  8. Apple’s FaceTime Reportedly Blocked in Russia Alongside Snapchat’s Video Calling Feature
  9. Anthropic Releases New Claude Tool That Interviews Users About Their AI Usage
  10. ACT Fibernet Launches Revamped Broadband Plans Starting at Rs. 499
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.