home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky sci.crypt:3212 alt.security:4357
- Newsgroups: sci.crypt,alt.security
- Path: sparky!uunet!spool.mu.edu!sdd.hp.com!wupost!usc!zaphod.mps.ohio-state.edu!n8emr!colnet!res
- From: res@colnet.cmhnet.org (Rob Stampfli)
- Subject: pgp2.0 signature security problem
- Message-ID: <1992Sep12.174358.11564@colnet.cmhnet.org>
- Organization: Little to None
- Date: Sat, 12 Sep 1992 17:43:58 GMT
- Lines: 19
-
- I recently had a chance to play around with pgp2.0 on a sVr2 Unix machine.
- There appears to be a big security problem with the signature mechanism:
- If you "sign" a file, and then add additional information to the end of
- the signed file, pgp includes this additional information as part of what
- it says you signed. For instance:
-
- echo 1 2 3 4 5 | pgp -fs >xyzzy.pgp
- echo 6 7 8 9 10 >>xyzzy.pgp
- pgp xyzzy.pgp
-
- pgp now tells me I have signed the phrase:
-
- 1 2 3 4 5
- 6 7 8 9 10
-
- when I have in fact only signed the first line.
- --
- Rob Stampfli rob@colnet.cmhnet.org The neat thing about standards:
- 614-864-9377 HAM RADIO: kd8wk@n8jyv.oh There are so many to choose from.
-