NEWS By Robert Lemos
Messages encrypted with the Pretty Good Privacy (PGP) algorithm could fall prey to a technique that fools senders into decoding their own secret messages, according to researchers.
The attack is known to work against the widely used open-source encryption software GNU Privacy Guard, but requires that the would-be spy first intercept the message and then convince the sender to decrypt what seems to be a second message.
A noted cryptographer, however, stressed that PGP is not broken.
"If I use this, I get one message - I don't get your (secret) key," said Bruce Schneier, founder and chief technology officer of network protection provider Counterpane Internet Security. Schneier proved the existence of the flaw with Jonathan Katz, a professor at the University of Maryland, and with one of Katz's graduate students.
Details of the attack method will be given at a lecture at the Information Security Conference in Brazil, later this year, and paper on the attack method is available now at the Counterpane site.
The attack takes advantage of a flaw that existed in the PGP standard until last year. Because the defense against the attack requires that developers break compatibility with older versions, the makers of many encryption programs haven't fixed the problem.
That's the case with GnuPG, said Jon Callas, principal author of the OpenPGP formats standard for the Internet Engineering Task Force, the group responsible for setting technical standards on the Internet.
"Schneier and Katz have come up with a practical attack against this weakness that we have known about for a while," he said. "It's mainly a con attack--one person has to convince another to do something."
PGP is an example of a public-key encryption system. Each person using PGP has a private key, which they keep secret, and a public key, which they publish. A message encrypted with the public key can be decrypted by the private key, and vice versa.
For an in-depth explanation of how PGP works and how the defect takes hold, click here http://www.silicon.com/a55074
Robert Lemos writes for News.com
PGP defect reveals encrypted messages
Pretty bad news...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




