[11487] in cryptography@c2.net mail archive
Re: [aleph1@securityfocus.com] Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG
daemon@ATHENA.MIT.EDU (Sidney Markowitz)
Tue Aug 13 15:14:46 2002
From: "Sidney Markowitz" <sidney@sidney.com>
To: <cryptography@wasabisystems.com>
Date: Tue, 13 Aug 2002 11:07:35 -0700
[Perry message forwarded a notice of a paper on an attack against PGP and
GnuPG]
A posting on bugtraq in response said, in part:
> From: "Werner Koch" <wk@gnupg.org>
[...]
> Countermeasures are defined in the OpenPGP drafts since October 2000.
>
> This MDC (Manipulation Detection Code) feature is supported since PGP
> 7.0 (decryption only) and GnuPG 1.0.2.
[...]
> The general problem is that the MDC feature is not compatible with any
> PGP versions before 7.0 or GnuPG 1.0.2.
The full posting is at http://online.securityfocus.com/archive/1/287127
-- sidney
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@wasabisystems.com