[15145] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: digsig - when a MAC or MD is good enough?

daemon@ATHENA.MIT.EDU (John Gilmore)
Sat Jan 3 18:09:23 2004

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
To: iang@systemics.com, gnu@new.toad.com
Cc: crypto <cryptography@metzdowd.com>
In-Reply-To: Message from Ian Grigg <iang@systemics.com> 
   of "Thu, 01 Jan 2004 21:03:34 EST." <3FF4D176.4B807840@systemics.com> 
Date: Sat, 03 Jan 2004 00:22:26 -0800
From: John Gilmore <gnu@toad.com>

> Sarbanes-Oxley Act in the US.  Section 1102 of that act:
>     Whoever corruptly--
>        "(1) alters, destroys, mutilates, or conceals a
>        record, document, or other object, or attempts to
>        do so, with the intent to impair the object's
>        integrity or availability for use in an official
>        proceeding; ...
>     shall be fined under this title or imprisoned not
>     more than 20 years, or both.".

The flaw in this ointment is the "intent" requirement.  Corporate
lawyers regularly advise their client companies to shred all
non-essential records older than, e.g. two years.  The big reason to
do so is to impair their availability in case of future litigation.
But if that intent becomes illegal, then the advice will be to shred
them "to reduce clutter" or "to save storage space".

> Can we surmise that a digital record with an MD attached and
> logged would fall within "object" ?

What's the point of keeping a message digest of a logged item?  If the
log can be altered, then the message digest can be altered to match.
(Imagine a sendmail log file, where each line is the same as now, but
ends with the MD of the line in some gibberish characters...)

	John

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post