Vik Bajaj on Sun, 27 Aug 2000 16:22:55 -0400 (EDT)


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] PGP ADK Vulnerability.


On Sun, Aug 27, 2000 at 04:19:31PM -0400, Beldon Dominello wrote:

> changing the checksum of the whole key itself.  Now, in the new version, it would
> seem that you can't do that (which is good) but an ADK could be added
> surreptitiously at creation time (which could be bad, as I think you described
> quite well in your response.

That is always true.  However, if you have control over the key creation
process, you may as well compromise the secret key and avoid the difficulty
of an ADK.

-V.


______________________________________________________________________
Philadelphia Linux Users Group       -      http://www.phillylinux.org
Announcements-http://lists.phillylinux.org/mail/listinfo/plug-announce
General Discussion  -  http://lists.phillylinux.org/mail/listinfo/plug