Re: How regularly is the GnuPG source code examined?

From: David Wagner (daw_at_taverner.cs.berkeley.edu)
Date: 09/28/05

  • Next message: David Wagner: "Re: Re-rolled Salsa20 function"
    Date: Wed, 28 Sep 2005 04:16:11 +0000 (UTC)
    
    

    Unruh wrote:
    >daw@taverner.cs.berkeley.edu (David Wagner) writes:
    >>I already gave one example of an apparently accidental bug in PGP that
    >>(a) allowed to attacker, intercepting only the output of the program,
    >>to gain enough information to decrypt it easily; (b) could have been
    >>inserted by an insider; (c) was in fact not detected for a long time.
    >
    >I vaguely recall that it was in the behaviour of the random number
    >generator wasn't it? Ie, the entropy of the generator was far smaller than
    >it should have been.

    Right.


  • Next message: David Wagner: "Re: Re-rolled Salsa20 function"

    Relevant Pages

    • Re: How regularly is the GnuPG source code examined?
      ... >>altered in such a way that the attacker, intercepting only the output from ... could gain enough information to decrypt it easily. ... the entropy of the generator was far smaller than ...
      (sci.crypt)
    • Re: Where do the random numbers come from?
      ... Which part of the protocol is too slow? ... Diffie-Hellman key exchange is too slow for you, ... key exchange so that an attacker can't fake it. ... the best-known random number generator used for non- ...
      (comp.security.ssh)
    • Re: A PRNG based on the DLP
      ... Legendre symbol gives me the least significant bit of the discrete ... Yes, but you (as an attacker) can't apply it, since E bits of the ... so far I have not set any constraints for this generator to be ... Shank's BSGS in 2^time and space. ...
      (sci.crypt)
    • Re: ID revisited ... ( Yet another reason for abandoning numerical
      ... a given piece of data is difficult to guess by an attacker. ... A cryptographically secure pseudo-random number generator is usually ... A stream cipher: a completely deterministic finite state machine ... An entropy gathering and seeding mechanism: ...
      (talk.origins)
    • Re: ID revisited ... ( Yet another reason for abandoning numerical
      ... a given piece of data is difficult to guess by an attacker. ... A cryptographically secure pseudo-random number generator is usually ... A stream cipher: a completely deterministic finite state machine ... An entropy gathering and seeding mechanism: ...
      (talk.origins)