subject: (Fwd) Re: [crypto] Paper on the Latest PGP Issue posted: Thu, 12 Apr 2001 16:09:58 +0100
------- Forwarded message follows -------
Date sent: Tue, 27 Mar 2001 17:52:55 -0500 (EST)
From: audit <[email protected]>
To: <[email protected]>
Subject: Re: [crypto] Paper on the Latest PGP Issue
Organization: Radiusnet.net
Send reply to:
Well.. The attack on the DSA key looks valid to me. Except that they
fail to mention that the signature produced with the modified key will
of course never validate, thus giving someone a clue that his key was
tampered with.
The version 3 RSA attack has been known for years and they present it
likes it was their idea. Don't know if that's arrogance or ignorance.
I didn't have time to analyze the V4 RSA attack, but from skimming over
it I am not entirely sure if it's possible. I'll leave that for the
die-hard cryptographers.. I am just a simple crypto-programmer :)
What is of course disgusting is the way they presented all of this. With
a full-blown press release without evidence backing it up or a warning
to the authors. Phil, Jon et al should have been notified and given a
chance to respond before the press release.
(Open)PGP has never claimed to be secure if someone has access to your
PC (they could do all sorts of nasty things) and that's why I don't
think this will have a major priority to be fixed.
It is something that shouldn't be there and that's why I think it will
be fixed.. eventually.
In the meantime, to be sure that your keys are fine, sign and verify
something before using your key :P
Erwin
------- End of forwarded message -------
generated by msg2page 0.06 on Jul 21, 2006 at 19:04:43