Re: Adding a nounce before hashing as covert channel
Andrew Gallagher via Gnupg-devel <[email protected]>
| Newsgroups | gmane.comp.encryption.gpg.devel |
|---|---|
| Message-ID | <[email protected]> |
On 17 Dec 2024, at 13:40, James Bottomley <[email protected]> wrote: > I admit, since you would most > need to execute this over the lifetime of a key and store as many > signatures as you can, that it's a nation state type of attack rather > than a quick hacker infiltration one. But these are also the types of > attack we need to guard against. The type of attack that you’re describing appears at first glance to have no better probability of success than random chance. If you could calculate how much better than random such a method might be, it would help us all understand how seriously to take the possibility. But even if it were worth considering, adding random salt would be expected to *decrease* the chances of a digest collision, so it would be an argument *for* salting. A _______________________________________________ Gnupg-devel mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-devel
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmdhloIACgkQXB7EBNWQ ZikGUQ//UW+dM7n/7M3PVA2R4uIlUp563HrZUIH4cC/EgikDJxDLoB3an1xwyQP2 4Jzup6gKgkpdmwJjqSTmgxTwkKVq0ynEdvGZXbXW1swtb95wN+IpRIH0kOrM2x8i 7pXBoM6qTwiVWtp8mg5emdkJoUZpWd/iecN6HkeMmcKtAZ6c5sac24UF0o8OpL/W cQ+56YVlT9VNMS4ELH0WbH2tqBpArpBCSBFbPo7hSZkAlPfPNsjOke3BsVI1GHRX HxOHePWwqHo81pn9vgcweLOUZXOuNNZkLa9/yDZLZfGVKLRRRhvgdxnxf6oiyWnl PEaHbiiRrj3srIVccQ65p9zKabL8D6F9ZDTxxGeek7bI2FmsgqLt/FqLSCi3+wwz xgFlx/QNEbSLL16b5xKVVJenNTF8sCgbGAQJQC8qe+BwWaDwK2XNSAgS8Acwz+N9 H2yFGcMpRW6Oeql+30epiqEPCOLf9t4Mp8fy8d6HKQZukHxCYTbMhNrfAnuYv0hb ubENBa8nr8fDoYeqZZfts6zQgkV/rbjn3wQyaxFTyVMKK+rqKyTt2BFDjB6+fzOe 9tHyzMN75YszPoxrNKCJ9KfpSSQOxPyrbVA0tan0M2EzeXbtLb+iJC/5pRcW29xm XFGnwoN9/k4nIdwhB2nu/1Dk4LNEcm55Ykzm872Kj7fl5metH3k= =ur/h -----END PGP SIGNATURE-----