HZFQ.COM
welcome to my space
X
Search:  
Welcome to:hzfq.com
Writing | Self Help | Travel | Wines and Spirits | Plastic Surgeries | Advertising | Forums | Banking | Related articles
NAVIGATION - HOME

PGP Flaw Leaves E-mails Vulnerable

Published by: admin 2008-11-20
Security researchers have unearthed a flaw within the popular PGP encryption tool that could allow snoopers to decode sensitive e-mails.

The Security Blanket::
File Format: Microsoft Word - View as HTMLAlways remember that unencrypted emails and instant messaging are like PGP is probably the most popular client encryption software on the Internet.
http://www.infoweb.state.ia.us/newsletter/security/blanket/docs/sb_august02.doc
HOME
PGP , or Pretty Good Privacy, is the defacto standard for encryption on the Internet and is widely thought of as invincible but researchers at Counterpane Internet Security Inc and Columbia University say they have found a way to modify a PGP-encrypted e-mail without having to descrambling it.

In an advisory, Counterpane said an attacker could repackage the message and pass the modified message on to the intended recipient of the original message.

It said the text within the message would appear as gibberish and could lead to a request for a resent. If the original text is included in the resend request, the adversary may be able to determine the original message.

Schneier on Security: My Talk at Defcon 15::
Oct 11, 2007 Bruce uses PGP disk. He divides the hard drive between long-term and about complex systems being more vulnerable than simple systems.]
http://www.schneier.com/blog/archives/2007/10/my_talk_at_defc.html
HOME
From editor@telecom-digest.org Tue Jun 22 15:34:40 2004 Received ::
From editor@telecom-digest.org Tue Jun 22 15:34:40 2004 Received: (from ptownson @localhost) by massis.lcs.mit.edu (8.11.6p3/8.11.3) id i5MJYeo12092; Tue,
http://massis.lcs.mit.edu/archives/back.issues/2004.volume.23/vol23.iss301-350
HOME
The detection of the flaw has forced an update to the OpenPGP standard, which is expected to be released Monday.

The researchers found the flaw in both PGP and GnuPG but noted that the attacks largely failed when data is compressed before encryption.

The Microsoft Security Response Center (MSRC)::
Third, while we use Pretty Good Privacy (PGP) to sign our security notification e-mails, the mere presence of a PGP signature block in an e-mail doesn’t
http://blogs.technet.com/msrc/
HOME
While the flaw is described as "serious," the researchers found it was very difficult to exploit and urged users of PGP to avoid including full text of messages when replying.

"Users of GnuPG and PGP should be aware that compression should not be turned off. Compression is turned on by default, but a user sending a compressed file will still be at risk from a chosen-ciphertext attack," according to the advisory. If compression is not used, or if compressed files are sent, the chosen-ciphertext attack could succeed against both GnuPG and PGP. The security outfit said GnuPG is also vulnerable if the user does not view the warning message that the encrypted data fails the message integrity check.

"In "batch mode "operation this warning would probably go unnoticed by the user since in this case the decrypted," it added.

The research showed the OpenPGP standard, as written, was vulnerable to chosen ciphertext attack due to the following:

  • No explicit requirement of a message integrity check.
  • Optional implementation of compression.
  • Requiring acceptance of "uncompressed" as a valid form of compression.
  • "Developers of front end software for GnuPG need to propagate integrity violation warnings to the users. This is important not only for protection against chosen ciphertext attacks -- integrity protection is useless if the user is not warned when it has been violated," the company said.


    Buffer Flaw Found in ToolTalk
    Fourth Release of Apache 2.0

    You are looking at:hzfq.com's PGP Flaw Leaves E-mails Vulnerable, click hzfq.com to home
    #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about PGP Flaw Leaves E-mails Vulnerable , Please add it free.

    About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
    Copyright© 2008 hzfq.com All Rights Reserved
    Site made&Support support@hzfq.com    E-mail: web@hzfq.com