[aleph1 at securityfocus.com] Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG

Sidney Markowitz sidney at sidney.com
Tue Aug 13 14:07:35 EDT 2002


[Perry message forwarded a notice of a paper on an attack against PGP and
GnuPG]

A posting on bugtraq in response said, in part:

> From: "Werner Koch" <wk at gnupg.org>
[...]
> Countermeasures are defined in the OpenPGP drafts since October 2000.
>
> This MDC (Manipulation Detection Code) feature is supported since PGP
> 7.0 (decryption only) and GnuPG 1.0.2.
[...]
> The general problem is that the MDC feature is not compatible with any
> PGP versions before 7.0 or GnuPG 1.0.2.

The full posting is at http://online.securityfocus.com/archive/1/287127

 -- sidney



---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at wasabisystems.com



More information about the cryptography mailing list