ietf-openpgp
[Top] [All Lists]

Re: message integrity checksum?

1998-01-06 17:42:48
-----BEGIN PGP SIGNED MESSAGE-----

On Tue, 6 Jan 1998, Adam Back wrote:

Gary Howland discussed PGP vulnerabilities at HIP97 I think.  One of
the vulnerabilities was that encrypted (but not signed) messages could
be altered undetectably.

This vulnerability is commen to any system that is encrypted but not
signed.  It is not a perculartity of PGP.  

Clearly one way to fix it is to use signatures.

Of cause.


- -- 
Please excuse my spelling as I suffer from agraphia see the url in my
header. Never trust a country with more peaple then sheep.  ex-net.scum
and proud You Say To People "Throw Off Your Chains" And They Make New
Chains For Themselves? --Terry Pratchett. 

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQCVAwUBNLK8OaQK0ynCmdStAQEjaAP/ZD1wWYJ5+gQYNitZEjLI3SaVdGYHEecz
UG8BZFPB7vsbZY4ZrPq9KTwdIGIf5ExNQwfh6piR77JbYJLMYcRZsdZM2V4t2neh
kne/3Db3RGzdsjM4RSykrGfsPcM2EPhOub/5/0YgDCPn7ot54KB0n9mai6+r3QoL
dTzb0tcpynU=
=j9J6
-----END PGP SIGNATURE-----


<Prev in Thread] Current Thread [Next in Thread>