Clearsigning in PGP 5.0 & Plug-ins: How secure?

Clearsigning in PGP 5.0 & Plug-ins: How secure?

Post by Jason Marti » Sat, 10 Jan 1998 04:00:00



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


> How secure and tamper-proof is clearsigning a message with PGP 5.0
and
> the plug-ins?

> I am not looking for a how-to, but rather for information on whether
clearsigning is
> secure or whether it can be compromised.

Very secure.  If even a single byte is changed in any way the
signature will be "bad".  In some occasions the mailer will some how
mangle the message by word-wrapping it or doing some funny CR/LF
translation.  This can cause a ordinarily "good" signature to read as
bad. In any case there is no modification you can make to a clear
signed message and still have the signature stay valid.

- -Jason

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.5.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBNLbEYUKfLTNHAEQFEQKiXACeNgvjWowrnMpDqajjKnCVkc6D7DEAn1Ai
SxK1GF2wjwiVDh3wwgUVFkj4
=+k1g
-----END PGP SIGNATURE-----

 
 
 

Clearsigning in PGP 5.0 & Plug-ins: How secure?

Post by Hans Bausewe » Sun, 11 Jan 1998 04:00:00



>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1


>> How secure and tamper-proof is clearsigning a message with PGP 5.0
>and
>> the plug-ins?

>> I am not looking for a how-to, but rather for information on whether
>clearsigning is
>> secure or whether it can be compromised.

>Very secure.  If even a single byte is changed in any way the
>signature will be "bad".  In some occasions the mailer will some how
>mangle the message by word-wrapping it or doing some funny CR/LF
>translation.  This can cause a ordinarily "good" signature to read as
>bad. In any case there is no modification you can make to a clear
>signed message and still have the signature stay valid.

Usually the problem is special (foreign language) character translations.

Hans


|
| My key is available from the keyservers and from my homepage
|------check http://www.xs4all.nl/~comerwel/: PGP-shell for Eudora!-------

 
 
 

1. Need pgp 5.0 freeware plug-ins for Netscape mail

You will highly appreciated if you tell me where I can get "pgp 5.0
freeware plug-ins for Netscape". Please give me an email copy when you
reply this message.

Thanks in advance.
--
===================================
Mike Wang
Senior System Administrator

Tel:    (86)21-63747668 x 3932
Fax:    (86)21-63743780 or 63743788

===================================

2. Textchanged event in Datagrid

3. Diffs between Plug-Ins in 4.0 and 5.0?

4. 720* Series Module question

5. PGP 5.0i - will it come with Plug-Ins?

6. help with overclocking FSB using IC chip

7. Possible Bug in PGP 6.0 and Outlook/OE Plug-ins

8. How to become a CA (certification authority) ?

9. ActiveX Acrobat Reader control & plug-ins?

10. Plug-ins, shareware & freeware for Acrobat pdf

11. Design plug-in with Acrobat plug-ins SDK

12. Scanning plug-ins

13. Mirrowind OXM Disc, Plug-Ins, Patches