R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

OpenPGP flaw confirmed

Czechoslovakian security group ICZ, which made a vague warning about vulnerabilities in PGP encryption software at the start of the week, has released a more detailed advisory of the flaw.

James Middleton, vnunet.com 22 Mar 2001
ADVERTISEMENT

Czechoslovakian security group ICZ, which made a vague warning about vulnerabilities in PGP encryption software at the start of the week, has released a more detailed advisory of the flaw.

The vulnerability seems to be inherent to OpenPGP, the security format proposed as a standard in relation to encryption and digital signatures. The format is used in other applications apart from PGP, including GNU Privacy Guard.

ICZ claims to have successfully verified and demonstrated the attack, which leaves private keys vulnerable, on PGP version 7.0.3, which is typically considered as highly secure.

Vlastimil Klima and Tomas Rosa, cryptologists at ICZ, have branded the protection offered by OpenPGP as "illusory", pointing out that attackers would not need to attack the cipher itself, but can simply bypass it as well as a user's password.

"A slight modification of the private key file followed by capturing a signed message is enough to break the private key," reads the advisory. A user's private key can then be calculated and the attacker can sign any message as the original user.

"The completed analysis of the OpenPGP format has discovered serious defects that make OpenPGP-based applications vulnerable. Similar vulnerabilities can be expected in other asymmetrical cryptographic systems, including systems based on elliptic curves," said Klima and Rosa.

As a result, ICZ is appealing for the very careful design of cryptographic systems.

The full advisory for the vulnerability can be found here.

See also:

Student discovers PGP flaw  20 Sep 2001
A group of security developers has called for an industry standard for internet security testing.  22 Mar 2001
Bug found in encryption software; Pressure group wants e-commons; Intel beefs up storage with German acquisition; Freeloader.com falls off bandwagon; DoubleClick announces job cuts.  21 Mar 2001
Godfather of encryption and creator of PGP, Phil Zimmermann, has moved over to security company Hush Communications, in a bid to set a global standard for encryption in digital communication and strike a killer blow for privacy on the web.  26 Feb 2001
Four separate vulnerabilities have been discovered in the software used by most of the internet's domain name system servers, putting parts of the network at risk.  30 Jan 2001
Hackers are aiming their technical weaponry at security vulnerabilities in company VPNs, security experts have warned.  15 Jun 2000

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Subject Matter Expert - Welwyn Garden City  Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at ... more >
Central London, United Kingdom | MI5 Security Services
Computer and Network Operations Centre Operator - Competitive + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and ... more >
Brentwood, Essex, United Kingdom | NHS Blood & Transplant
System Support Officer - Brentwood - £20,225 - £26,123 The National Blood Service is an integral part of the NHS. Operating a network of centres across England and North Wales, we collect around 2 million ... more >
Central London, United Kingdom | MI5 Security Service
Experienced UNIX Developer - Up to £50,000 + benefits -Central London As an experienced UNIX Developer, you will be responsible for product development, integration, configuration and evaluation on UNIX and .net platforms. You will have ... more >
More job opportunities