Re: Cryptologists Discover Flaw in PGP

"Amaron" <[email protected]>
Newsgroups gmane.ietf.ediint
Message-ID <000a01c0b251$53b2dd60$010101c8@lilian>
I can't believe where people may have gotten the idea that the private key
is safe or useless without the passphrase.  The proponents of PGP have
always said that you must keep your private key safe.  After all, most
people will not use a passphrase much longer than a normal password - eg. 8
to 12 characters which is easily broken using an automated trial and error
attack, once you have the private key file and an encrypted message.  Isn't
that why smart-cards were invented?

This supposed 'revelation' is nothing of the sort; it's just a fact that has
not been as widely published as it should have been.
Regards,
Bjorn Schmid.
-----Original Message-----
From: Robert C. Lyons <[email protected]>
To: [email protected] <[email protected]>
Date: Thursday, 22 March 2001 3:31
Subject: Cryptologists Discover Flaw in PGP


>See http://www.i.cz/en/onas/tisk4.html
>for the official press release.
>
>The flaw sounds serious. In a nutshell, a
>hacker can obtain your private key if
>he can obtain your private key file
>and a message signed by your private key.
>Your private key file contains your
>encrypted private key, which is decrypted
>using your passphrase. PGP users believe
>that the private key file is useless
>unless you know the passphrase. It turns
>out that that belief is not true.
>
>A technical paper about the flaw will
>be available at http://www.icz.cz/ (or
>http://www.icz.cz/en/index.html for
>non-Czech speakers) on Friday.
>
>Page A14 of today's New York Times also
>has the story.
>
>Best regards,
>
>Bob
>
><sig name    = 'Bob Lyons'
>     title   = 'B2B Integration Consultant'
>     company = 'Unidex, Inc.'
>     phone   = '+1-732-975-9877'
>     email   = '[email protected]'
>     url     = 'http://www.unidex.com/'
>     product = 'XML Convert: transforms flat files to XML and vice versa'
/>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.