TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OpenPGP SEIP downgrade attack

43 pointsby mukyuover 9 years ago

3 comments

tptacekover 9 years ago
The flaw he appears to be talking about is that the OpenPGP MDC doesn&#x27;t cover metadata; the message must be parsed to recover the authenticator before the authenticator can be checked, and so the ciphertext is malleable.<p>The properties he&#x27;s talking about for CFB are largely true of CTR as well (the gold standard in streaming modes). I think, by suggesting PGP use a &quot;different mode&quot;, he may instead mean it would be better if PGP used an authenticated encryption mode.<p>Authentication is a weak spot for PGP, since its design predates much of authenticated cryptography.
评论 #10353370 未加载
评论 #10353675 未加载
adrianNover 9 years ago
So the message is: don&#x27;t trust the integrity of encrypted mails unless the signature is valid? That doesn&#x27;t seem too terrible.
nickpsecurityover 9 years ago
GPG comes through again. Not ideally but acceptably for the paranoids. :)