Digi-Oek.ch · @DigiOekCH
3 followers · 20 posts · Server social.tchncs.de

(3/3)
Countermeasures for developers/OpenPGP standard: (1) avoid attacks by OpenPGP specification not leaving the task of confirming key to individual . (2) Use an scheme (3). Deprecating encryption option in OpenPGP spec.

Paper & Info: kopenpgp.com/

#ko #KeyOverwritingAttack #verschlüsselung #encryption #e2e #pgp #openpgp #elgamal #aead #implementations #integrity #KOKV

Last updated 3 years ago

John Goerzen · @jgoerzen
714 followers · 2223 posts · Server floss.social

@liw Not entirely. My scenario involves using the decryptor in a pipe, both for the data coming in and the data going out. A signature over the entire file of course can't be verified until the entire file's processed, so at best it could withhold just the last block of data. AFAICT, /#HMAC can apply to each block, and thus can prevent even one byte of un-authenticated data from being output. So, I think can promise to never emit unauthenticated data, but can't.

#OpenPGP #age #aead

Last updated 4 years ago