[11487] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [aleph1@securityfocus.com] Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG

daemon@ATHENA.MIT.EDU (Sidney Markowitz)
Tue Aug 13 15:14:46 2002

From: "Sidney Markowitz" <sidney@sidney.com>
To: <cryptography@wasabisystems.com>
Date: Tue, 13 Aug 2002 11:07:35 -0700

[Perry message forwarded a notice of a paper on an attack against PGP and
GnuPG]

A posting on bugtraq in response said, in part:

> From: "Werner Koch" <wk@gnupg.org>
[...]
> Countermeasures are defined in the OpenPGP drafts since October 2000.
>
> This MDC (Manipulation Detection Code) feature is supported since PGP
> 7.0 (decryption only) and GnuPG 1.0.2.
[...]
> The general problem is that the MDC feature is not compatible with any
> PGP versions before 7.0 or GnuPG 1.0.2.

The full posting is at http://online.securityfocus.com/archive/1/287127

 -- sidney



---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@wasabisystems.com

home help back first fref pref prev next nref lref last post