home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: sci.crypt
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!cs.utexas.edu!qt.cs.utexas.edu!yale.edu!ira.uka.de!Sirius.dfn.de!news.DKRZ-Hamburg.DE!rzsun2.informatik.uni-hamburg.de!fbihh!bontchev
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Subject: Re: Zimmermann's responses to Sidelnikov's PGP critique
- Message-ID: <bontchev.726792428@fbihh>
- Sender: news@informatik.uni-hamburg.de (Mr. News)
- Reply-To: bontchev@fbihh.informatik.uni-hamburg.de
- Organization: Virus Test Center, University of Hamburg
- References: <1993Jan8.223337.14551@athena.mit.edu>
- Date: 11 Jan 93 22:47:08 GMT
- Lines: 27
-
- tytso@ATHENA.MIT.EDU (Theodore Ts'o) writes:
-
- > >> - when considering the hashing function as the automatic device
- > >>without output, it is enough simply possible to construct the
- > >>image of reverse automatic device and with using the blanks in
- > >>text files (or free fields in some standard formats as in DBF),
- > >>to compensate the hashing function at changed file to former
- > >>significance.
-
- > I interpreted this to mean that Dr. Sidelnikov believes that there is a
- > design flaw in MD5, which is the hashing function used by PGP. Perhaps
-
- I don't believe even that... Look, suppose -you- have found a flaw in
- MD5 and were to comment about PGP. What would you say? "The hashing
- function in PGP seems simple enough to defeat"? No, you would say "PGP
- uses MD5 as a hashing function and as it has been shown (reference my
- paper, or the results of my lab or whatever), it is easy enough to
- break it".... My guess here is that Dr. Sidelnikov either hasn't
- noticed that PGP uses MD5, or does not know what MD5 is...
-
- Regards,
- Vesselin
- --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-