RE: Cryptologists Discover Flaw in PGP

"Robert C. Lyons" <[email protected]>
Newsgroups gmane.ietf.ediint
Message-ID <[email protected]>
Bjorn wrote:
> I can't believe where people may have gotten the idea that the private key
> is safe or useless without the passphrase.  The proponents of PGP have
> always said that you must keep your private key safe.

The following excerpts from my PGP User's Manual
would lead some (if not many) people to believe
that the private key file can not be decrypted
without the passphrase:

*	"No one can use your private key without this pass phrase."

*	"Do not lose this pass phrase. There is no way to recover it
       if you lose it. If you lose it, you will no longer be able
       to use this key to decrypt your message, or digitally sign
       messages you send. If you forget it, forget it!"

On page 37 of "Protect Your Privacy, A Guide for PGP Users"
(ISBN 0-13-185596-4), the author states:

	"... even if someone steals your private key ring, it will do
	them no good without the passphrase."

Both books do emphasize the importance of choosing secure
passphrases. The quotes above are based on the assumption
that the user has chosen a secure passphrase.

> After all, most
> people will not use a passphrase much longer than a normal password - eg.
8
> to 12 characters which is easily broken using an automated trial and error
> attack, once you have the private key file and an encrypted message.
Isn't
> that why smart-cards were invented?

I agree that many users probably choose weak passphrases.

According to my PGP product literature, the effort required
to crack a 1024-bit public key is roughly equal to the
effort required to guess (by brute force) a 15 word passphrase.
In other words, if you want a passphrase that is as secure
as a 1024-bit public key, then you'll need a 15 word passphrase
(or, a 16 character passphrase, such that each character is
one of 64 possible characters).

A more reasonable approach is to use a strong passphrase of
reasonable length and keep the private key safe (as you suggest).

> This supposed 'revelation' is nothing of the sort; it's just a fact that
has
> not been as widely published as it should have been.

I think that press release is significant, especially if
you are a PGP user who has gone through the trouble of choosing
a secure passphrase and who is concerned that an unauthorized
individual could obtain your private key file.

The ICZ press release states that it takes only half a second
to crack the private key file using the newly discovered
attack. It would take far longer to guess a strong passphrase.

Best regards,

Bob

<sig name    = 'Bob Lyons'
     title   = 'B2B Integration Consultant'
     company = 'Unidex, Inc.'
     phone   = '+1-732-975-9877'
     email   = '[email protected]'
     url     = 'http://www.unidex.com/'
     product = 'XML Convert: transforms flat files to XML and vice versa' />
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.