ideal.dll

vedaal at nym.hush.com vedaal at nym.hush.com
Fri Jun 22 18:39:12 CEST 2012


On Fri, 22 Jun 2012 11:23:27 -0400 David Shaw 
<dshaw at jabberwocky.com> wrote:

>There is more than one attack against V3.  There is the "bit 
>sliding" attack, where you can forge the whole fingerprint, but as 

>a side effect it changes the keysize, and there is the DEADBEEF 
>attack where you can forge the key ID, but not the fingerprint.  I 

>believe Daniel is referring to DEADBEEF here.
>
>Using DEADBEEF, I can make a V3 key with a 64-bit key ID without 
>affecting the keysize.  


>I just sent you a private mail containing a key with your key ID 
>;)


Thanks,
Cute ;-)

but as I posted earlier,

" trivially countered by 
simply listing the keysize together with the fingerprint."


vedaal





More information about the Gnupg-users mailing list