[11484] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

[aleph1@securityfocus.com] Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG

daemon@ATHENA.MIT.EDU (Perry E. Metzger)
Tue Aug 13 12:25:38 2002

To: cryptography@wasabisystems.com
From: "Perry E. Metzger" <perry@piermont.com>
Date: 13 Aug 2002 12:18:21 -0400

--=-=-=
Content-Type: message/rfc822
Content-Disposition: inline

Date: Mon, 12 Aug 2002 11:45:26 -0600
From: aleph1@securityfocus.com
To: secpapers@securityfocus.com, bugtraq@securityfocus.com
Subject: Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG
Message-ID: <20020812174526.GL17476@securityfocus.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii

Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG
K. Jallad, J. Katz, and B. Schneier

We recently noted that PGP and other e-mail encryption protocols are, in 
theory, highly vulnerable to chosen-ciphertext attacks in which the recipient 
of the e-mail acts as an unwitting "decryption oracle." We argued further 
that such attacks are quite feasible and therefore represent a serious 
concern. Here, we investigate these claims in more detail by attempting to 
implement the suggested attacks. On one hand, we are able to successfully 
implement the described attacks against PGP and GnuPG (two widely-used 
software packages) in a number of different settings. On the other hand, we 
show that the attacks largely fail when data is compressed before encryption.

Interestingly,the attacks are unsuccessful for largely fortuitous reasons; 
resistance to these attacks does not seem due to any conscious effort made to 
prevent them. Based on our work, we discuss those instances in which 
chosen-ciphertext attacks do indeed represent an important threat and hence 
must be taken into account in order to maintain confidentiality. We also 
recommend changes in the OpenPGP standard to reduce the effectiveness of our 
attacks in these settings. 

http://www.counterpane.com/pgp-attack.pdf
http://www.counterpane.com/pgp-attack.ps.zip

-- 
Elias Levy
Symantec
Alea jacta est


--=-=-=



-- 
Perry E. Metzger		perry@piermont.com
--
"Ask not what your country can force other people to do for you..."

--=-=-=--

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@wasabisystems.com

home help back first fref pref prev next nref lref last post