Re: Automate GPG or PGP to make an .exe
- From: Paul Rubin <http://phr.cx@xxxxxxxxxxxxxx>
- Date: 29 Mar 2006 02:16:56 -0800
"TC" <gg.20.keen4some@xxxxxxxxxxxxxxx> writes:
(4) Creates an EXE file which, when run on a target PC, will:
(a) Fire up the symmetric cipher;
(b) Prompt the user for the secret key, then
(c) Decrypt the file accordingly.
Color me stupid, but, I am struggling to see the problem with this.
Please elucidate the holes in that process.
An attacker can substitute a malicious .exe for the real one, and the
user then enters the secret password into it. Oops.
.
- Follow-Ups:
- References:
- Automate GPG or PGP to make an .exe
- From: crypt-o-time
- Re: Automate GPG or PGP to make an .exe
- From: Unruh
- Re: Automate GPG or PGP to make an .exe
- From: TC
- Re: Automate GPG or PGP to make an .exe
- From: Sebastian Gottschalk
- Re: Automate GPG or PGP to make an .exe
- From: TC
- Automate GPG or PGP to make an .exe
- Prev by Date: Re: Automate GPG or PGP to make an .exe
- Next by Date: Re: Automate GPG or PGP to make an .exe
- Previous by thread: Re: Automate GPG or PGP to make an .exe
- Next by thread: Re: Automate GPG or PGP to make an .exe
- Index(es):
Relevant Pages
|
|