RE: secure sign & encrypt

"Dominikus Scherkl" <Dominikus.Scherkl@glueckkanja.com> Thu, 23 May 2002 15:50 UTC

Received: from above.proper.com (mail.imc.org [208.184.76.43]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA15477 for <openpgp-archive@odin.ietf.org>; Thu, 23 May 2002 11:50:16 -0400 (EDT)
Received: by above.proper.com (8.11.6/8.11.3) id g4NFeoH06223 for ietf-openpgp-bks; Thu, 23 May 2002 08:40:50 -0700 (PDT)
Received: from guk1d002.glueckkanja.org (mail.glueckkanja.com [62.8.243.3]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g4NFenL06219 for <ietf-openpgp@imc.org>; Thu, 23 May 2002 08:40:50 -0700 (PDT)
content-class: urn:content-classes:message
Subject: RE: secure sign & encrypt
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Thu, 23 May 2002 17:40:45 +0200
X-MimeOLE: Produced By Microsoft Exchange V6.0.5762.3
Message-ID: <2F89C141B5B67645BB56C038537578821B58CA@guk1d002.glueckkanja.org>
Thread-Topic: secure sign & encrypt
Thread-Index: AcICZSy4NfgnE8BTTXuIkzX1WZqMjQACkHIg
From: Dominikus Scherkl <Dominikus.Scherkl@glueckkanja.com>
To: Terje Braaten <Terje.Braaten@concept.fr>
Cc: ietf-openpgp@imc.org
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id g4NFeoL06220
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
Content-Transfer-Encoding: 8bit

Hi!

> > Your proposal for an extra packet does not address this alleged
flaw.
> > Note that Alice could sign a message saying "encrypted to 
> > Bob", and then
> > encrypt and send the message to Charlie, thus framing Bob for breach
> > of confidence.
> 
> No, because then Charlie would know it was something fishy going on.
> He would not now if Alice or Bob (or some one else) was to blame,
> but he would get a warning message saying that this is an invalid
> signed & encrypted message.
Hey, this is an attack at _Bob_ - Charlie don't needs to be nice!
The simple possibility of such attacks discredits the trust in beeing
the original receiver of a message, so we gain nothing!

Best Regards.
-- 
Dominikus Scherkl
dominikus.scherkl@glueckkanja.com