Re: Suggested updates for the Privacy Handbook?

Werner Koch <[email protected]> Fri, 18 Oct 2013 09:18:08 +0200
Newsgroups gmane.comp.encryption.gpg.documentation
Message-ID <[email protected]>
On Fri, 18 Oct 2013 06:50, [email protected] said:

> * Phasing out SHA1 and MD5 hashing and moving from DSA to RSA keys (see https://www.debian-administration.org/users/dkg/weblog/48 for info.)

FWIW, GnuPG used MD5 only for PGP2 compatibility.  From rfc-4880:

   Implementations MUST implement SHA-1.  Implementations MAY implement
   other algorithms.  MD5 is deprecated.

SHA-1 is is an important part of OpenPGP and used in ways which are
resistant against collision attacks.  Thus it is not easy to fade it
out.  A paragraph explaining why certain algorithms re used by default
does make sense; though.


> * Using frontends such as GPGTools for the MacOSX platform and GPG4win for the Windows platform.
> * The limitations of GPG with regard to protecting against attacks against an end user's system.

Yes, that is important for real world security.


Shalom-Salam,

   Werner


-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.