ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Disabling compression in OpenPGP

2014-03-19 16:16:35
On Wed, Mar 19, 2014 at 1:47 PM, Jon Callas <jon(_at_)callas(_dot_)org> wrote:
What's being leaked by compression? Really, I don't get it.

Some people like a demonstration.

Consider that I'm going to cast one of two ballots in a secret ballot
election. The ballots are just permutations of eachother so they are
the same size.

https://people.xiph.org/~greg/ballot.1
https://people.xiph.org/~greg/ballot.2

I encrypt my secret ballot to the election officials with the public
key at https://people.xiph.org/~greg/openpgp_testpubkey.asc

using the command:
gpg -ear 9C28FC94 --compress-algo ZIP --compress-level 9 ballot.X
(just being explicit for consistency sake, using GPG 1.4.16 in Fedora
19)

And I get the encrypted result of
https://people.xiph.org/~greg/ballot.secret.asc

Which ballot did I cast?   Anyone?

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp