Re: ciphire encrypted mail tool

From: Alan (a__l__a__n_at_hotmail.com)
Date: 01/21/05


Date: Fri, 21 Jan 2005 11:11:16 -0500


"Juergen Nieveler" <juergen.nieveler.nospam@arcor.de> wrote in message
news:Xns95E5A9F75C4FAjuergennieveler@nieveler.org...
Volker Hetzer" <volker.hetzer@ieee.org> wrote:
> How would you do an MITM?

And Juergen answered:
> Put the keyserver address in the hosts-file with a wrong IP, put a fake
> keyserver at that IP, intercept the request for other public keys and
> replace them with keys you own, then intercept the outbound messages,
> decrypt, store, reencrypt with the real public keys.

I'm not sure that would work, except perhaps in limited circumstances.
Somehow the substituted certificate would have to include the intended
recipient's email address, but the attacker's public key. All this would
have to be signed by a CA whose certificate is signed by the root CA. So
only someone trusted by the root CA could do this. So, for example, law
enforcement might be able to do this and get away with it. Someone else
might be able to do this until caught, after which their CA certificate
would likely be revoked.

Alan



Relevant Pages

  • Re: Proposal for a new PKI model (At least I hope its new)
    ... That is say I trust Paul Rubin's public key. ... two basic reasons for the SSL server domain name certificate: ... certificates have to check with the domain name infrastructure to see ... CA/PKI industry is that public keys be registered with the domain name ...
    (sci.crypt)
  • Re: What is a Certificate?
    ... > signature on the certificate was generated by its own key, ... basically there you have a trusted repository of public keys. ... CA public keys are also typically in a trusted repository of public ...
    (comp.security.misc)
  • Re: Are ++ and -- operators really more efficient
    ... But you still need a way to verify that it's the right key. ... the signature contains a URL indicating ... where the certificate can be found. ... (This idea that public keys represent principals -- ...
    (comp.lang.c)
  • Re: What is a Certificate?
    ... > Certificate Authority by its signature. ... When you start an SSL ... information that is being certified by the certification authorities. ... public keys at the same time domain names are obtained. ...
    (comp.security.misc)
  • Re: PGP Key-ID ausreichend zur Zuordnung eines Public Keys?
    ... > Reicht es für das Auffinden eines Public Keys auf einem Keyserver nur ... > oder sind noch andere Angaben für eine eindeutige Zuordnung notwendig? ... > Key-ID zu geben (damit wir nicht die Public Keys selber speichern müssen). ...
    (de.comp.security.misc)

Quantcast