vedaal at vedaal at
Fri Jun 22 18:39:12 CEST 2012

On Fri, 22 Jun 2012 11:23:27 -0400 David Shaw 
<dshaw at> wrote:

>There is more than one attack against V3.  There is the "bit 
>sliding" attack, where you can forge the whole fingerprint, but as 

>a side effect it changes the keysize, and there is the DEADBEEF 
>attack where you can forge the key ID, but not the fingerprint.  I 

>believe Daniel is referring to DEADBEEF here.
>Using DEADBEEF, I can make a V3 key with a 64-bit key ID without 
>affecting the keysize.  

>I just sent you a private mail containing a key with your key ID 

Cute ;-)

but as I posted earlier,

" trivially countered by 
simply listing the keysize together with the fingerprint."


More information about the Gnupg-users mailing list