[openpgp] Re: on discarding Literal Data Packet metadata [ was: Analysis document]
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 13 Jul 2025, at 17:35, Daniel Kahn Gillmor <[email protected]> wrote: > > Clearly, all these "automated and semi-automated" processes are broken, > to whatever extent they're relying on integrity and authenticity of the > filename/mtime information. If we can't even identify them, i don't > know how we can provide fixes to the protocol that will be meaningful at > an application layer. It would be possible in principle to update an API to sign over the metadata (which must already be provided if the application is vulnerable), to fail the signature verification if the metadata has been modified, and to return safe default values if the metadata subpacket is missing (unix timestamp zero, “decrypted-file” or some such). No deep knowledge of the application should be required, as the happy path would be unchanged, and the entire point is to create a new unhappy path. A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmh0J/sACgkQXB7EBNWQ Zil07Q/+KmwLJ0YDoLv+4KDEoauYqYoRK2REPeMywqdQ4sf/kLTdhl9N8YGw2MeI tdAap8AZNCWquyw7jjqcsIBWYUw0TYjU5XOAcHNLmN5NbHdt6ZByHC7Y4r0fYZOP uJfA4I1Vu9RG9Ee5gIdt3SLJTjegjEEJ8xjVM0phUQWG9lanu2TZmHurAd4t+KWH X7BhzwEgRKcFKnQTlTuJlQRRGrzW7glhpQsr19qPrCWSzoLbQmDlnsJPNLKKZIVG LuvTgKlzH4+9l5c/PryPFhovB8YukwAPajlPLWgvBWZL/uJY7q03cCKUixll0iCf HPEdz+JJ7YRA7a7URWNPZZK43XWOm7AF4+tq2wb3P+xpeDjS7UzeCT4F8f00ny3K XOsI3o1aAe5TzOH/DOxpsk0NoHtevTmV804KPIQTauxEjhXsfn+jhRKBRbpOHTzD t+gRnO76nN0qS9+zARJKRf4ECyDNol9OM+jEhV9w44v8Omu7xnkO96Qtk9p+b71e ZmSepaGy+XM+8+QCMHTOZCBuqQFMiaRmbhWtiEi5NcN6a5fkBgJsohzC/iJxViKg 3d6FPxA2lVBsjrqvkPYPDMtevZ0tKqLjKVeuBV27fwT5vn9MaZQNKkTd4li7goO5 4k3puqrT5kNaSsvJ/usA9dmLclkwqD5cjg4tK/hqTGheomjSR9U= =ixBY -----END PGP SIGNATURE-----