internally signed JPEG files

David Shaw dshaw@jabberwocky.com
Mon Apr 14 21:35:01 2003


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sun, Apr 13, 2003 at 02:27:48PM +0200, Sascha Ren=C3=A9 Leib wrote:
> Hello all,
>=20
> sorry if this has been discussed here already, I am new to this list,=20
> but before I spend my weekend coding I rather ask if somebody has=20
> already done this before.. :-)
>=20
> I am planning to add a GPG/PGP signature to a JPEG file. However, the=20
> usual procedure of posting a hash key with the file does not appear=20
> very user-friendly to me, that's why I would rather like to go another=20
> way. In short:
>  - create a signature for the JPEG-Data stream
>  - insert this signature in a new marker segment in the JPEG file.

I haven't heard of anyone doing something like this with JPEG files,
but it seems like an interesting idea to me, and not very difficult at
all to do.

One bit I'd be concerned about is:

> Since JPEG viewers should ignore unknown marker segments, this should=20
> not affect average end-users who can still view them conveniently in=20
> their web browsers, etc.

The scary word there is "should" ;) I'd be interested to see how this
works out in practice with different JPEG viewers.

David
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2rc1 (GNU/Linux)
Comment: http://www.jabberwocky.com/david/keys.asc

iD8DBQE+mw1/4mZch0nhy8kRAs/NAJ9n7qp9wpnwCfoQZ0uxlSc1Ks8MxACeNUUZ
dLlAKunYZQG144lM9sUMRSY=3D
=3Dx0bL
-----END PGP SIGNATURE-----