FW: Inquiry

Andrew McDonald andrew@mcdonald.org.uk
Tue Oct 16 22:36:01 2001


On Tue, Oct 16, 2001 at 05:59:17PM +0100, Owen Blacker wrote:
[self decrypting archives]

> To be fair, there are plenty of other reasons for SDAs -- I think
> they're great for sending information to people who I don't think would
> be able to install PGP or GnuPG. And some people aren't able to install
> software on their systems.
I think SDAs have one big problem (as I think previous threads here have picked up). There is no integrity protection. How do you know that the mail hasn't been intercepted on route and the interceptor added a stub to the executable that captures the password and sends it back to them? -- Andrew McDonald E-mail: andrew@mcdonald.org.uk http://www.mcdonald.org.uk/andrew/