First off I wanted to say a big congrats on an awesome presentation last
night Aaron!

I was thinking about the multiple recipients thing last night and think
I still disagree that you can not encrypt messages to multiple people.
My reasoning:

The crypto used in public key cryptography is really slow right.  So
instead of encrypting the entire messsage with that algorithm doesn't
GPG generate a random key, encrypt your data with a fast symmetric
cipher using that key, and then encrypt a copy of that key to the
recipient?  Same idea as with SSL when it's negotiating a key to use for
it's symmetric cipher.

So assuming this is true, which I'm fairly sure it is, wouldn't
encrypting to multiple recipients just attach one copy of the symmetric
key encrypted for each recipient.  The message data itself would still
only appear once in the GPG output and would be encrypted using the
symmetric cipher.

Jeff

-- 
Jeff Clement 
GPG Signature: 2956 42A8 ED8A 91F4 8CE0  A5DF 5293 8E10 6F08 7FB9
Website      : http://jclement.ca

Attachment: msg03730/pgp00000.pgp
Description: PGP signature

Reply via email to