ietf-smime
[Top] [All Lists]

Re: Simplifying S/MIME v3

1997-10-14 15:00:23
signedandEnvelopedData has a flaw.  An attacker can stip the signature from
the message, then by changing the OID, the recipient will think that the
message we encrypted.

This attack is mitigated by using signedData and envelopedData independently.

Russ

<Prev in Thread] Current Thread [Next in Thread>