ietf-openpgp
[Top] [All Lists]

Re: [openpgp] 4880bis: Compression (was: details of 4880bis work)

2015-04-15 17:49:17
On Wed, 2015-04-15 at 14:42 -0400, Phillip Hallam-Baker wrote: 
Compression provides an oracle for the plaintext
Only when the attacker can do chosen plain text... and basically we
can't really prevent the user from manually doing compression (thereby
introducing the same oracle).

Nevertheless, unless there are real crypto advantages of using
compression (which I guess there are not), I agree that it's really time
to remove it from OpenPGP,... we're a crypto message standard - not a
compression standard.


Cheers,
Chris. 

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp