Re: attack against ElGamal (and related algorithms)
From: Paul Rubin (//phr.cx_at_NOSPAM.invalid)
Date: 12/21/03
- Next message: Marcel Martin: "Re: ECB 1.0 beta 1"
- Previous message: Roger Schlafly: "Re: RSA vs DH"
- Next in thread: Atom 'Smasher': "Re: attack against ElGamal (and related algorithms)"
- Reply: Atom 'Smasher': "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: John E. Hadstate: "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: Tom St Denis: "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: Jarod: "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: Bryan Olson: "Re: attack against ElGamal (and related algorithms)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 21 Dec 2003 03:06:17 -0800
Atom 'Smasher' <ngbz@fhfcvpvbhf.bet> writes:
> 1) Eve has Bob's public key (it is, after all, public).
> 2) Eve's copy of PGP (or GnuPG, etc) is modified to use the same
> "k" every time.
> 3) Eve can encrypt as many messages as she wants, using Bob's public key
> and a fixed "k". (Eve knows the plain-text, the cipher-text, "k",
> and the public-key)
> 4) Eve can then recover Bob's private key.
No no, that's a misreading. To get Bob's private key, she'd have to
modify Bob's copy of PGP to re-use k, and then get Bob to sign two
different messages with the same k, not modify her own copy. If she
modifies her own copy as you suggest and then signs multiple messages,
then she can recover her own private key, but she already knows her
own private key so doesn't need to recover it.
- Next message: Marcel Martin: "Re: ECB 1.0 beta 1"
- Previous message: Roger Schlafly: "Re: RSA vs DH"
- Next in thread: Atom 'Smasher': "Re: attack against ElGamal (and related algorithms)"
- Reply: Atom 'Smasher': "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: John E. Hadstate: "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: Tom St Denis: "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: Jarod: "Re: attack against ElGamal (and related algorithms)"
- Maybe reply: Bryan Olson: "Re: attack against ElGamal (and related algorithms)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|