Re: Suggested updates for the Privacy Handbook?
Werner Koch <[email protected]> Fri, 18 Oct 2013 09:18:08 +0200
| Newsgroups | gmane.comp.encryption.gpg.documentation |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 18 Oct 2013 06:50, [email protected] said: > * Phasing out SHA1 and MD5 hashing and moving from DSA to RSA keys (see https://www.debian-administration.org/users/dkg/weblog/48 for info.) FWIW, GnuPG used MD5 only for PGP2 compatibility. From rfc-4880: Implementations MUST implement SHA-1. Implementations MAY implement other algorithms. MD5 is deprecated. SHA-1 is is an important part of OpenPGP and used in ways which are resistant against collision attacks. Thus it is not easy to fade it out. A paragraph explaining why certain algorithms re used by default does make sense; though. > * Using frontends such as GPGTools for the MacOSX platform and GPG4win for the Windows platform. > * The limitations of GPG with regard to protecting against attacks against an end user's system. Yes, that is important for real world security. Shalom-Salam, Werner -- Die Gedanken sind frei. Ausnahmen regelt ein Bundesgesetz.