session key curiosity ???

vedaal at hush.com vedaal at hush.com
Thu Sep 29 01:42:06 CEST 2005


now that have finally gotten 
decryption with the session key to work ;-),
discovered something very curious ...

this was the 'good' command with the session key string:

gpg --override-session-key 
2:1568A79A26ABCB75C294AA07AB73C53A7D168F2B898F93BE c:\r\s.txt

when retyping, i accidentally changed the last character to an F 
instead of an E

and it *still* worked!

should this be?

or is the last character of the session string also an identifier 
of some sort, but not really part of the key that was used to 
encrypt/decrypt?

for reference and reproducibility,
here is the original encrypted message:

-----BEGIN PGP MESSAGE-----
Version: GnuPG v1.4.2 (MingW32) 
Comment: Acts of Kindness better the World, and protect the Soul

hQEOA9kZp67w50lIEAQAq8301JNDrLFkpxOessXpzJZP/yd7Ejw6nrzPsMiCzSDH
sD53TaV2+mz89QkD/L4ZWrBGLetpxJ4hbAZqIYMNnLwRq3Ip3VSNLvG0b+CHuMH4
fBIEnj07JkjZ+zB9VBvSIWePqXiSWDKbNBGcVrWCKnqKnEn1JkZRdfcxbjys7PIE
AI4aB6uITbtEUrFTcXLgVUMnVi7qLNQtdg+t9j7BiLJnq4Hoe7g/VV5LzqXuVYsQ
FQCEpt4CotgaMWM20GUJvGyvsy1CAhHK4ZeQy8elc2ouHm/H48oUBBEG2343fqAW
zcbaaFPWaBIBeAg/ntTxb5HPLTm8nQnHnST0Tar9XKkhhQIMA6yhY/YEre4gARAA
kGM+IWtMKipvr2GBzzh9HxdpLKvGv9jRXnv9gRTpiv85v6Iz+eOe5NL6e5L+FaiN
5fMObEMp2MnqMap6FSwPqT9ibDjzO+eGbaWngkXMdkY3FyuRbij1+x8boVVYK1WK
sHRmFAiDe5JKFB06h812B75zML72px+wJNuDWTUhtynSrsfJ72kuq1GD3wz0UZSh
GcfDzMu7U7DgPqRice31afDQdhbL08TibSxgY9mrTA2cPQakOKRFzwNNywl5/gCb
iXoBz1nFMVbXbMSEoVvKy2IyOcVOH9mNL9ZBaeMfW2wFvjAOpWPkuEPyy8SWxhRt
pzmIFcDFOew6w9wkewQcqWl0vFHAWx4hdvgB/xRbNMCuJ85ff91mbBV0Z1SzxGrJ
YDEH6I9Aum/41aCXDrYE/kkyfgI1pHss2JT95DqL1w0G2uKaO5FPKJxVUZmD3ojk
wEV+43YggiQ2GXKgC8PDX5Za+U/08BqqQnxy1UuKtq3RU0yIZ06CevXqhVbtCQre
Y5hW5uwhLe3wp8jkSK6avaSs4MvKePO0FAsCRdEAZBWJGohYHZ9w8LfYB5ynbLeA
1SnAYgVTVUDNGw1kEraBIe98qFlGpI77lGxbRK3l/TSDYbCB9JDqREzDVi+tTKW/
Hg5YSb+wKyBfy04iscZVQ3xzN/WTBpJ07q6utaKD0j3SPwHAmF3UB/mPbbOYLIaN
MemUCLbrz0x8HpluBRw0V04n8zK5Ip5tU2Dg4UwGcAf76nunrol0WAHVxJ6xZ2RK
9A==
=Lxsg


try both these session keys on whatever filename you save the 
message as

gpg --override-session-key 
2:1568A79A26ABCB75C294AA07AB73C53A7D168F2B898F93BF filename

gpg --override-session-key 
2:1568A79A26ABCB75C294AA07AB73C53A7D168F2B898F93BE filename


tia,

vedaal



Concerned about your privacy? Follow this link to get
secure FREE email: http://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
http://www.hushmail.com/services-messenger?l=434

Promote security and make money with the Hushmail Affiliate Program: 
http://www.hushmail.com/about-affiliate?l=427




More information about the Gnupg-users mailing list