[Fwd: Czech attack to PGP]
Charles Lindsey
Charles Lindsey <chl at clw.cs.man.ac.uk>
Sun, 25 Mar 2001 10:17:21 +0100 (BST)
On Fri, 23 Mar 2001 12:25:01 +0000
Tim Waugh <twaugh@redhat.com> said...
>
> On Fri, Mar 23, 2001 at 10:06:13AM +0000, Charles Lindsey wrote:
>
> > 6. "Certainly" says Plod. "Here is a copy of it on this floppy disc"
> > (but of course it isn't - it has been Czeched). So you sign his test
> > document (your passphrase and key appear to work correctly) and give it
> > back to Plod.
>
> You need to verify the signed test document against your public key
> before giving it back to Plod.
I had understood that the Czech trick still produced apparently valid
signatures (it was not clear from what has been posted so far). If not,
then that would be a wise precaution.
Charles H. Lindsey ---------At Home, doing my own thing------------------------
Tel: +44 161 436 6131 Fax: +44 161 436 6133 Web: http://www.cs.man.ac.uk/~chl
Email: chl@clw.cs.man.ac.uk Snail: 5 Clerewood Ave, CHEADLE, SK8 3JU, U.K.
PGP: 2C15F1A9 Fingerprint: 73 6D C2 51 93 A0 01 E7 65 E8 64 7E 14 A4 AB A5