ietf-openpgp
[Top] [All Lists]

Re: PGPticket

1998-06-08 10:01:19
On 6/7/98, Men from Black Helicopters forced Bill Stewart to write:

Is appending the nonce good enough, or should you really prepend as well?
The problem is that lots of applications can potentially be tricked by
 sign( "syntactically-correct-stuff,junk" )
while they're less likely to accept messages with the junk first.


this is a great point! well taken..

I will fix this in the protocol..

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Vinnie Moscaritolo
Wordwide Developer Technical Support
N&C/Hardware

Apple Computer, Inc.                      email:  vinnie(_at_)apple(_dot_)com
3 Infinite Loop, MS: 303-2T               phone:      408.974.5560
Cupertino, CA 95014                       fax:        408.862.7602
Fingerprint:     0AAF 9A74 113F 7FDD 97E6 04BD 1D7A 2D86 6F17 2A0A
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



<Prev in Thread] Current Thread [Next in Thread>