FW: Inquiry
Andrew McDonald
andrew@mcdonald.org.uk
Tue Oct 16 22:36:01 2001
On Tue, Oct 16, 2001 at 05:59:17PM +0100, Owen Blacker wrote:
[self decrypting archives]
> To be fair, there are plenty of other reasons for SDAs -- I think
> they're great for sending information to people who I don't think would
> be able to install PGP or GnuPG. And some people aren't able to install
> software on their systems.
I think SDAs have one big problem (as I think previous threads here
have picked up). There is no integrity protection.
How do you know that the mail hasn't been intercepted on route and the
interceptor added a stub to the executable that captures the password
and sends it back to them?
--
Andrew McDonald
E-mail: andrew@mcdonald.org.uk
http://www.mcdonald.org.uk/andrew/