Live data from Hacker News

PGP Marks 30th Anniversary

philzimmermann.com

81–82 of 82 posts

Re: PGP Marks 30th Anniversary

#81
post #71

Earlier quoted context omitted.

the knowledge of the first 11 bytes/characters of the unencrypted message. You probably know how that worked out for the Enigma.

I am not suggesting that email clients should entirely depend on OpenPGP email inherent resistance to oracle attacks, only pointing out that it exists. Presumably the Enigma operators were not putting their decrypted messages in envelopes before sending them off to their enemies. Efail was primarily a straight up plain text leak. Plain text attacks come in distinct categories. The block ciphers used in OpenPGP are ge…

I think when you're at the point in your argument where the bar you're setting is "immunity to the attacks that broke Enigma", you might as well just concede.

Re: PGP Marks 30th Anniversary

#82
post #61

Earlier quoted context omitted.

You are not. Of course, the problem is that PGP doesn't get its informal resilience to single-bit errors through error-correcting codes on the ciphertext.

To be clear, OpenPGP does not correct errors. You still end up with corrupted data. It is just that you get back all your good data, no matter where it is in the file.

So you're saying that not only does OpenPGP release unauthenticated plaintext to callers, but it doesn't even implement the feature that takes advantage of it. Good note.

What's crazy about this is that you can get error correction without using insecure 1990s cryptography, simply by forward error correcting your ciphertext. I'm really having a hard time even getting my head around the argument you've managed to devise here.

Post reply on HN