ietf-openpgp
[Top] [All Lists]

Re: Some thoughts on a v5 key and why it shouldn't be a mess (fwd)

2005-09-22 13:12:25

On Thu, Sep 22, 2005 at 09:18:36PM +0200, Daniel A. Nagy wrote:

On Thu, Sep 22, 2005 at 09:00:00PM +0200, Konrad Rosenbaum wrote:

Let's say MDX is broken by some genius.

Remember, that the key ID is the last 8 (or four) byes of the fingerprint.
If MDX is broken, one can generatet a key with an arbitrary ID.

Well yes, but someone can generate a key with an arbitrary ID today.
Even forgetting the DEADBEEF games that are possible with v3 RSA keys,
there is a program out there that generates v4 DSA keys over and over
until the requested (short) key ID comes up.

David