pem-dev
[Top] [All Lists]

Re: A brief comparison of email encryption protocols

1996-02-19 19:04:00

Raph:

At 4:49 PM 2/14/96, Raph Levien wrote:
  MOSS is mostly cryptographically sound.

In fact, MOSS is too flexible.  In most circumstances, signatures should be 
performed before encryption.  MOSS allows people to sign ciphertext, by 
putting a multipart/encrypted inside a multipart/signed.  The MOSS 
specification offers no warnings about this "feature."

Russ

<Prev in Thread] Current Thread [Next in Thread>