GPG PGP S/Mime vulnerability

Julia A. Case
Thu Aug 9 14:35:02 2001

Quoting Anthony E. Greene (

> I think he means the From, To, Date, and Subject headers, all of which are
> known to the mail client at the time of composition. If mail clients
> inserted this data into the message before calling PGP, that would be an
> automated solution to the problem, assuming these headers had enough
> specific information to be of any help.
I'm still to sure this would work well, I mean do you require that the From: address match one of the addresses in the signing key? The previously indicated methods of making sure you don't sign ambigous mails seems the better choice.

Julia