ietf-openpgp
[Top] [All Lists]

Re: Bellcore Attack

2001-03-21 17:51:33
You can see the press release at <http://www.i.cz/en/onas/tisk4.html>.
There are also things in Czech on their web site. Supposedly, the details
will be published tomorrow.

The gist, as much as we know of it now is that they claim that they can
write into a V3 secret key (the PGP 2.6 format) in such a way as to force
you to make signatures that the attacker can then forge. We don't know the
details yet. They only want to talk to reporters, not to technical people.
All the details I have are ones I wheedled out of reporters. I sent mail to
the contact on the press release yesterday who said that we have to wait
like everyone else. Some mail today going directly to the cryptographers
involved got a reply that said they'll publish tomorrow. So we'll see.

        Jon

<Prev in Thread] Current Thread [Next in Thread>