Subject: 
         [PGP-USERS] A group of Czech cryptographers has claimed to have
broken OpenPGP...
    Date: 
         Wed, 21 Mar 2001 21:19:26 -0500
    From: 
         Robert Guerra <[EMAIL PROTECTED]>
Reply-To: 
         [EMAIL PROTECTED]
      To: 
         "PGP-User's Mailing List" <[EMAIL PROTECTED]>


http://securitygeeks.shmoo.com/article.php?story=20010320130246610

OpenPGP Broken?

Contributed by: jon   March 20 2001 @ 01:02PM

A group of Czech cryptographers has claimed to have broken OpenPGP. 
There are few details out yet, and most of what there are are in 
Czech. I've gotten a press release sent to me, and have been looking 
at it.

Here are the details I have. I have a press release from the 
marketing director of ICZ in the Czech Republic. There's a web site 
at http://www.i.cz for the company. I have also been forwarded a mail 
message from Bugtraq with similar puzzlement to my own.

They claim on the one hand that this is a bug in the OpenPGP format 
itself (full disclosure -- I'm the editor and one of the authors of 
OpenPGP Formats (http://www.ietf.org/rfc/rfc2440.txt). On the other 
hand, they also claim that it's a bug in the implementation in PGP 
7.0.3.

The claim appears to be that if you have someone's private key file, 
and a signature, then you can extract the private key. Beyond that, 
there is hype and hand-wringing.

With the little bit of information I have, I'm skeptical. The private 
key format of OpenPGP is such that the private key is encrypted with 
a symmetric cipher, the key of that is derived from your passphrase. 
(See RFC2440 for details.) It could be that there's some weird 
interaction that leaks information about the secret key. But that's 
not an OpenPGP problem, that's a cipher problem. It could also be 
that there's a leak in a DSA signature. Discrete logarithm ciphers 
have the problem that they need some random nonce in a signature, and 
if that nonce leaks, then the private key can be derived. But I don't 
see how that could happen, either.

I'll also admit that I'm skeptical for a number of other reasons that 
have nothing to do with technology. First of all, people claim to 
find breaks in PGP all the time, and it inevitably turns out to be 
wrong, or some known problem -- like if you lose your passphrase 
people can decrypt your private key. Secondly, the cryptographers who 
found the flaw did not post it to the OpenPGP mailing list, or any of 
the other usual venues; they held a press conference, two days before 
CEBIT, during an IETF meeting (and coincidentally, the very day of 
the OpenPGP meeting). This makes my left eyebrow lift. If you have a 
bombshell, there's a good way to publicize it. Light the fuse, and 
drop it in cypherpunks, cryptography, and bugtraq. Stand back and 
watch the fun. Instead, we have a press release with a marketing 
contact, no details, and a penultimate sentence that reads, "In the 
end of their research report, the authors propose cryptographic 
measures correcting OpenPGP format and PGP(tm) program as well." (sic)

Cool. Tell us what the break is, and what your measures are. We're 
waiting. Security and crypto thrives on clever people coming up with 
devious things. Good ones make me giggle, and there's a Nietzschean 
aspect to security design. Each break makes the protocol stronger
-- 

--
Robert Guerra <[EMAIL PROTECTED]>, Fax: +1(303) 484-0302
WWW Page <http://pgp.greatvideo.com>, ICQ # 10266626
PGPKeys  <http://pgp.greatvideo.com/keys/rguerra/>

....................................................................
Unsubscribe:
<mailto:[EMAIL PROTECTED]?body=unsubscribe>
Automated Help/Info:
<mailto:[EMAIL PROTECTED]?body=help>
List Homepage: <http://cryptorights.org/pgp-users/>
List Admin (human): <mailto:[EMAIL PROTECTED]>
Please do not send administrative commands to the list address!  Thanks.


-- 
            http://www.bearerinstruments.com

         A Directory of Web sites and Internet 
          presences accepting non-fiat monies.

http://www.bearerinstruments.com/assets/BIMDsPGPkey.txt
650C 51DA 734F 697F 5706 3D6A 7712 BCC9 D1AE 00BA

---
You are currently subscribed to e-gold-list as: [email protected]
To unsubscribe send a blank email to [EMAIL PROTECTED]

Reply via email to