You are here: silicon.com > Software > Security Strategy

Security Strategy

Security shock: Cryptologists find flaw in PGP

Top cryptologists claim they have found a serious flaw in OpenPGP, which could blow open one of the most commonly used forms of encryption software.

By Pia Heikkila

Published: 22 March 2001 18:30 GMT

If confirmed, products such as Network Associates' email encryption software, Pretty Good Privacy (PGP), could be seriously flawed, leaving users' private keys open to attack.

Czech cryptologists working for a company called ICZ claim to have discovered the bug whilst working on a government security project.

Miroslav Votruba, marketing manager for ICZ, explained the scientists discovery: "The user's digital signature is protected by an encrypted key or cipher. We've proved that attackers do not need to attack the cipher itself, but they can simply bypass it as well as the user's password. A small alteration of the private key file followed by a capturing of a signed message is enough to break the private key," he said.

Neil Barrett, one of UK's top security specialists, said the study signals the most significant discovery as it is the first time anyone has managed to crack an OpenPGP system. "It is a very interesting finding as it is the first of its kind. The question is, will this be the beginning of more cryptography attacks to come or just an isolated vulnerability," he said.

But Douglas Hurd, business development manager for PGP at Network Associates, said that the Czech's discovery only goes half way to proving there is a vulnerability in the company's product.

"They are suggesting if the person is able to get access to your private key inside your PC, it is theoretically possible to modify the key and put it back to your PC and then capture something which is signed with the modified key. But in order for this attack to be possible, the attacker should be able to have open access to your PC," he said.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Communications Delivery Manager

The team is all about blending creativity with discipline, shaping engaging and informative internal communications in collaboration with Group ...

Vulnerability / Penetration tester (CEH) -

An immediate opening has arisen for a penetration / Vulnerability tester who also has a broad general Info sec background. My client is a FTSE 100 ...

C++ Tick Data specialist - Algorithmic Trading, London City

For more information or a discrete conversation, please apply now; vax@montash.com Vax Bahram Montash Associates Hedge Funds / High Frequency Prop ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: