Fwd: crypto flaw in secure mail standards

Mon Jun 25 18:09:01 2001

On Mon, Jun 25, 2001 at 11:21:07AM -0400, Anthony E. Greene wrote:

> On Mon, 25 Jun 2001, David Shaw wrote:
> >After reading the paper, I was thinking about a different way to
> >address the problem: encrypt the clear signature.
> But how would that stop Bob from misusing that sig later? Using the
> example of the cancelled deal, Bob could still decrypt the sig and the
> document (if necessary) and send the whole package to Charlie to lead
> Charlie to believe that Alice had canceled the Alice/Charlie deal.
I think I wasn't clear in my email. The hypothetical encrypted sig would of course contain the key id(s) of who it was signed to in the signed material. :) It is similar to Don Davis' suggestion to include a receipient list in the signed material. The main difference is that I'm suggesting making it an option for clearsigned documents, and making it possible to have the sign-to key be different than the encrypt-to key.