TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

OpenPGP SEIP downgrade attack

43 点作者 mukyu超过 9 年前

3 条评论

tptacek超过 9 年前
The flaw he appears to be talking about is that the OpenPGP MDC doesn&#x27;t cover metadata; the message must be parsed to recover the authenticator before the authenticator can be checked, and so the ciphertext is malleable.<p>The properties he&#x27;s talking about for CFB are largely true of CTR as well (the gold standard in streaming modes). I think, by suggesting PGP use a &quot;different mode&quot;, he may instead mean it would be better if PGP used an authenticated encryption mode.<p>Authentication is a weak spot for PGP, since its design predates much of authenticated cryptography.
评论 #10353370 未加载
评论 #10353675 未加载
adrianN超过 9 年前
So the message is: don&#x27;t trust the integrity of encrypted mails unless the signature is valid? That doesn&#x27;t seem too terrible.
nickpsecurity超过 9 年前
GPG comes through again. Not ideally but acceptably for the paranoids. :)