[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [NTSEC] pgp 5.0 back door



At 12:17 PM 9/29/97 -0400, Anonymous wrote:
>The PGP Web site in http://www.pgp.com/products/differences.cgi has a list
>of differences between PGP 5.0 (personal PGP) and PGP 4.5.x (corporate
>PGP).  The corporate one includes a feature that the private one doesn't
>called "message recovery".  Given Phil's fanaticism outlined above, this
>presumably isn't any way to get at the plaintext without the user's
>knowledge or cooperation, but just what the heck IS it?  I can't find a
>description of the feature on-line.  The manual itself is on-line in PDF,
>which presumably answers this question for acrobat fans.  I see nothing
>about "message recovery" in the hard-copy PGP 4.5 manual.

It is my understanding that this is a setting to force 4.5 to encrypt all
messages to a specified key, which would be the corporate "message
recovery" key.  PGP 5.0 has a similar feature--a check box labeled "always
decrypt to default key" in the settings.  When this box is checked, the
default public key (usually one of yours) will always appear in the
recipient list when encrypting a message.  In 5.0, the default key is
visible in the recipient list, and it can easily be remived via drag and
drop.  I think that 4.5.x didn't show the key, and didn't allow the user to
remove it.


Jonathan Wienke

What part of "the right of the people to keep and bear Arms, shall not be
infringed" is too hard to understand? (From 2nd Amendment, U.S. Constitution)

PGP 2.6.2 RSA Key Fingerprint: 7484 2FB7 7588 ACD1  3A8F 778A 7407 2928
DSS/D-H Key Fingerprint: 3312 6597 8258 9A9E D9FA  4878 C245 D245 EAA7 0DCC
Public keys available at pgpkeys.mit.edu. PGP encrypted e-mail preferred.

Get your assault crypto before they ban it!

US/Canadian Windows 95/NT or Mac users:
Get Eudora Light + PGP 5.0 for free at http://www.eudora.com/eudoralight/
Get PGP 5.0 for free at http://bs.mit.edu:8001/pgp-form.html

Non-US PGP 5.0 sources:
http://www.ifi.uio.no/pgp/
http://www.heise.de/ct/pgpCA/download.shtml
ftp://ftp.pca.dfn.de/pub/pgp/V5.0/
ftp://ftp.fu-berlin.de/pub/pc/win95/pgp
ftp://ftp.fu-berlin.de/pub/mac/pgp
http://www.shopmiami.com/utopia.hacktic.nl/pub/replay/pub/pgp/pgp50/win/

RSA export-o-matic:
print pack"C*",split/\D+/,`echo "16iII*o\U@{$/=$z;[(pop,pop,unpack"H*",<>
)]}\EsMsKsN0[lN*1lK[d2%Sa2/d0<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<J]dsJxp"|dc`

PGP signature