Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG

From: aleph1@securityfocus.com
Date: 08/12/02


Date: Mon, 12 Aug 2002 11:45:26 -0600
From: aleph1@securityfocus.com
To: secpapers@securityfocus.com, bugtraq@securityfocus.com

Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG
K. Jallad, J. Katz, and B. Schneier

We recently noted that PGP and other e-mail encryption protocols are, in
theory, highly vulnerable to chosen-ciphertext attacks in which the recipient
of the e-mail acts as an unwitting "decryption oracle." We argued further
that such attacks are quite feasible and therefore represent a serious
concern. Here, we investigate these claims in more detail by attempting to
implement the suggested attacks. On one hand, we are able to successfully
implement the described attacks against PGP and GnuPG (two widely-used
software packages) in a number of different settings. On the other hand, we
show that the attacks largely fail when data is compressed before encryption.

Interestingly,the attacks are unsuccessful for largely fortuitous reasons;
resistance to these attacks does not seem due to any conscious effort made to
prevent them. Based on our work, we discuss those instances in which
chosen-ciphertext attacks do indeed represent an important threat and hence
must be taken into account in order to maintain confidentiality. We also
recommend changes in the OpenPGP standard to reduce the effectiveness of our
attacks in these settings.

http://www.counterpane.com/pgp-attack.pdf
http://www.counterpane.com/pgp-attack.ps.zip

-- 
Elias Levy
Symantec
Alea jacta est



Relevant Pages

  • Re: PGP 9.0
    ... I think that 2003 was about the end for free PGP encryption binaries on Microsoft Windows or Apple OS. ... Undesirable elements would not use stolen credit or identities to facilitate purchase of licensed software products. ... Up to 75% of cyber attacks are launched on shopping carts, ... Check your website for ...
    (Pen-Test)
  • RE: PGP 9.0
    ... I believe PGP stopped being free after version 8 if im not mistaken. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Hackers are concentrating their efforts on attacking applications on your ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
    (Pen-Test)
  • Re: PGP 9.0
    ... Here you may download the latest ... freeware PGP version for your platform. ... >>Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
    (Pen-Test)
  • Re: Access to Vigay.com
    ... The attacks would be different but they wouldn't stop. ... PGP is a good solution. ... anybody serious about security knows that security by ... as secure if everybody used it. ...
    (comp.sys.acorn.misc)
  • RE: PGP 9.0
    ... We are a PGP Universal reseller and I have been working with the Server side ... the mail server if you are using imap/popand it will encrypt the message ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
    (Pen-Test)

Quantcast