Subject:
[PGP-USERS] A group of Czech cryptographers has claimed to have
broken OpenPGP...
Date:
Wed, 21 Mar 2001 21:19:26 -0500
From:
Robert Guerra <[EMAIL PROTECTED]>
Reply-To:
[EMAIL PROTECTED]
To:
"PGP-User's Mailing List" <[EMAIL PROTECTED]>
http://securitygeeks.shmoo.com/article.php?story=20010320130246610
OpenPGP Broken?
Contributed by: jon March 20 2001 @ 01:02PM
A group of Czech cryptographers has claimed to have broken OpenPGP.
There are few details out yet, and most of what there are are in
Czech. I've gotten a press release sent to me, and have been looking
at it.
Here are the details I have. I have a press release from the
marketing director of ICZ in the Czech Republic. There's a web site
at http://www.i.cz for the company. I have also been forwarded a mail
message from Bugtraq with similar puzzlement to my own.
They claim on the one hand that this is a bug in the OpenPGP format
itself (full disclosure -- I'm the editor and one of the authors of
OpenPGP Formats (http://www.ietf.org/rfc/rfc2440.txt). On the other
hand, they also claim that it's a bug in the implementation in PGP
7.0.3.
The claim appears to be that if you have someone's private key file,
and a signature, then you can extract the private key. Beyond that,
there is hype and hand-wringing.
With the little bit of information I have, I'm skeptical. The private
key format of OpenPGP is such that the private key is encrypted with
a symmetric cipher, the key of that is derived from your passphrase.
(See RFC2440 for details.) It could be that there's some weird
interaction that leaks information about the secret key. But that's
not an OpenPGP problem, that's a cipher problem. It could also be
that there's a leak in a DSA signature. Discrete logarithm ciphers
have the problem that they need some random nonce in a signature, and
if that nonce leaks, then the private key can be derived. But I don't
see how that could happen, either.
I'll also admit that I'm skeptical for a number of other reasons that
have nothing to do with technology. First of all, people claim to
find breaks in PGP all the time, and it inevitably turns out to be
wrong, or some known problem -- like if you lose your passphrase
people can decrypt your private key. Secondly, the cryptographers who
found the flaw did not post it to the OpenPGP mailing list, or any of
the other usual venues; they held a press conference, two days before
CEBIT, during an IETF meeting (and coincidentally, the very day of
the OpenPGP meeting). This makes my left eyebrow lift. If you have a
bombshell, there's a good way to publicize it. Light the fuse, and
drop it in cypherpunks, cryptography, and bugtraq. Stand back and
watch the fun. Instead, we have a press release with a marketing
contact, no details, and a penultimate sentence that reads, "In the
end of their research report, the authors propose cryptographic
measures correcting OpenPGP format and PGP(tm) program as well." (sic)
Cool. Tell us what the break is, and what your measures are. We're
waiting. Security and crypto thrives on clever people coming up with
devious things. Good ones make me giggle, and there's a Nietzschean
aspect to security design. Each break makes the protocol stronger
--
--
Robert Guerra <[EMAIL PROTECTED]>, Fax: +1(303) 484-0302
WWW Page <http://pgp.greatvideo.com>, ICQ # 10266626
PGPKeys <http://pgp.greatvideo.com/keys/rguerra/>
....................................................................
Unsubscribe:
<mailto:[EMAIL PROTECTED]?body=unsubscribe>
Automated Help/Info:
<mailto:[EMAIL PROTECTED]?body=help>
List Homepage: <http://cryptorights.org/pgp-users/>
List Admin (human): <mailto:[EMAIL PROTECTED]>
Please do not send administrative commands to the list address! Thanks.
--
http://www.bearerinstruments.com
A Directory of Web sites and Internet
presences accepting non-fiat monies.
http://www.bearerinstruments.com/assets/BIMDsPGPkey.txt
650C 51DA 734F 697F 5706 3D6A 7712 BCC9 D1AE 00BA
---
You are currently subscribed to e-gold-list as: [email protected]
To unsubscribe send a blank email to [EMAIL PROTECTED]