ietf-openpgp
[Top] [All Lists]

Re: Short intro on the K-R attack [Re: private key language]

2005-12-30 01:55:45

On Thu, Dec 29, 2005 at 03:13:19PM -0800, Jon Callas wrote:

I propose that we improve the packets when we do V5, but put in the  
security consideration now. Does that sound reasonable?

I agree that putting in the security consideration now is a reasonable thing
to do. As for the packet format, I would like to phase out encrypted private
key packets as such. Unencrypted private key packets encapsulated into
MDC-protected encrypted packets with an S2K in front of them does the job
and leaves us with one less format to maintain. I think, V5 should not have
an encrypted version at all.

-- 
Daniel