Bogus digital signatures, Re: OT: utility account transfer frauds

John R T Brazier prunesquallor at proproco.co.uk
Mon, 14 Oct 2002 22:50:09 +0100


> Charles confirmed:
> The snag I mentioned only arises if you have a
> signature to hand without the text it is alleged to sign, and then you
> cannot know the MD5 hash.

Absolutely. Under these conditions you've got to get hold of the hash, and
then match it. No help from the birthday 'paradox' here.

TTFN

John B