[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

TruthMonger key's password!





Anonymous writes on cpunks (blank subject field from [email protected]
earlier today).

> -----BEGIN PGP SIGNED MESSAGE-----
> 
> September 19, 1998, U.S. Medical Center for Federal
> Prisoners, Springfield, Missouri, not a Magic Circle.
> 
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2
> 
> iQCVAwUBNgPkchp0s99tXiQlAQEoHQP+IX2GivNiJpIB3ryiu+bte0+YyJRTZDWB
> bbF/qRIGrOOVKpNxuu+riAz0oUxHW3xuooPmIVcR8O0tfXljrxyAvK4qdtPFWyr9
> +PaE5clU7XdRqxiKGfao569W1vRPJW5vlmUm+/BHmRF1ADG/HqTy/EbivKEvZGcw
> UmrV65r+9ho=
> =wa8X
> -----END PGP SIGNATURE-----

That one I can verify the signature of (unlike the 0x2541C535 key-id
signed post which I proposed we try a signature attack on because of
lack of public key), because I have on my keyring the secret key since
adding the secret key to my key ring from this post which was made to
cypherpunks [1] with headers below (look in the archives, or copied
below):

: From: [email protected] (Anonymous)
: To: [email protected]
: Date: Tue, 23 Sep 1997 01:58:52 +0200 (MET DST)
: Subject: Persistent Persona

The key in that message was:

Type Bits/KeyID    Date       User ID
sec  1024/6D5E2425 2041/12/07 TruthMonger

-----BEGIN PGP SECRET KEY BLOCK-----
Version: 2.6.3i

lQHgA4dN5oIAAAEEAM/3b3wHc1iQEmtk9NQhmrHmZmlCdZH4T3kf2APlwA/NRsfU
pAa++0pBdgMMOr9QBMWNWuRuZriEUE/jH9cdMkgBeOrvsviFSe2wN074LrCZSugO
6KabPwokodYl8+R8xY5NC1pZUD4sYf49L6xOwpjiXukrRKqwABp0s99tXiQlAAUR
ARwSOk76t7D7A/0n7XVeJ5qLKatxrzKZ1+U9PLhEeeQkknETkj9aFmRNrj/I4n/Y
TgxKh74zK1/kM4y6bunTNU6+pBDPrvYJgqoq4kMlS3jXNdGBFn0Tw0j2klSZpXzA
Tb593tKD66dztQXiYbYYhydQixUp22NwjruiIfwjFdtU7tOhKfLgZ+dGJQIAH40N
9Gpt3oSQ+ua6I1mOEYzWXdH8HdaNQKxGVRYVH71Wi2TpDLuZbbYq6RB9LDQ0VJO0
6DumKr1OSG32zda+kwIAvjPYd8xEOyCo2NJfL2ZUBh9/GC9nb9UTxdwFP7AFx0F7
DTA+prGb672ly3NAa7/gje2W4isd3NN+T6T13WHmcAH+MnnMDMclF/hNKrhR39aB
1ZvVEBh8yz8xWCm5BQOqp55KyJGgDY0kAcwqejE0PHV8dMG6TVteVvOu7D7GDFcB
4KXvtAtUcnV0aE1vbmdlcg==
=HBLx
-----END PGP SECRET KEY BLOCK-----

which means that anyone can create such signatures.

That PGP correctly copes with signatures made by keys it has only a
private key for (and no public key) is something of a surprise -- PGP
must be smart enough to use the private key if the public key isn't
around on the keyring.  (The public key is a subset of private key).

Erk! just tried to create a signed file with that private key, and I
didn't notice before when I commented on the posting of this key that
key has a passphrase!  It wouldn't be one of those John Young
forwarded to the list from an anonymous source would it....

Holy smoke!  Now we are getting somewhere, the person who remailed
those passphrases to John Young knew that keys passphrase, and yet the
key was posted back in Sep 97!

John Young writes on cpunks:
> This allegedly is forwarded from CJ, though from an unknown source 
> so think twice:
> 
>       "Passwords:  sog, sog709, sog709cejCJP,sog709cjpCEJ, D'Shauneaux, 
>       D'shauneaux, and others..."

The passphrase was sog709.  Try it and see.  Check in the archives for
yourself for that message, (subject 'Persistent Persona') and become
paranoid!

What is going on here?  Is Toto still at large, drunk behind the
keyboard?  Is Toto not one person?  Or have the IRS extracted Carl
Johnson's passphrases from him and got busy playing mind-games with
us?

Adam

[1]
======================================================================
Date: Tue, 23 Sep 1997 01:58:52 +0200 (MET DST)
Subject: Persistent Persona
To: [email protected]
From: [email protected] (Anonymous)

-----BEGIN PGP MESSAGE-----
Version: 2.6.2

lQHgA4dN5oIAAAEEAM/3b3wHc1iQEmtk9NQhmrHmZmlCdZH4T3kf2APlwA/NRsfU
pAa++0pBdgMMOr9QBMWNWuRuZriEUE/jH9cdMkgBeOrvsviFSe2wN074LrCZSugO
6KabPwokodYl8+R8xY5NC1pZUD4sYf49L6xOwpjiXukrRKqwABp0s99tXiQlAAUR
ARwSOk76t7D7A/0n7XVeJ5qLKatxrzKZ1+U9PLhEeeQkknETkj9aFmRNrj/I4n/Y
TgxKh74zK1/kM4y6bunTNU6+pBDPrvYJgqoq4kMlS3jXNdGBFn0Tw0j2klSZpXzA
Tb593tKD66dztQXiYbYYhydQixUp22NwjruiIfwjFdtU7tOhKfLgZ+dGJQIAH40N
9Gpt3oSQ+ua6I1mOEYzWXdH8HdaNQKxGVRYVH71Wi2TpDLuZbbYq6RB9LDQ0VJO0
6DumKr1OSG32zda+kwIAvjPYd8xEOyCo2NJfL2ZUBh9/GC9nb9UTxdwFP7AFx0F7
DTA+prGb672ly3NAa7/gje2W4isd3NN+T6T13WHmcAH+MnnMDMclF/hNKrhR39aB
1ZvVEBh8yz8xWCm5BQOqp55KyJGgDY0kAcwqejE0PHV8dMG6TVteVvOu7D7GDFcB
4KXvtAtUcnV0aE1vbmdlcg==
=HBLx
-----END PGP MESSAGE-----

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.2

mQENAzOCm1EAAAEIANB5WCFbEjUhNaZ2cEWuh9xcP48QBixzJpxPqGc0Sogj9W1L
ezM5GDF0tZp5ksNbWf5+ErNxXo0yOM7LjDl+sRrEmcbuTkjqPJxG/q4JZ7Al3/FF
h1SFGWpQNz9BPewgHS8/Lp9Ywl+ELeau+FPrr/xmktYifBBaaPUTS5oNMhn4Ih0r
yez6WFn6lRYz+FLsXchjkg+I22tC1aD6iKv/BxCM//GzJ8UNkE7Vx94jZxJ/0vqE
3msqN1coj99okoggWzR5xe/wcLjUjXBw4Z208zhKNEC1AemkJV5HSbztfOgpZOqX
4dwsSDREfFcerM3gusIv3Gz+oU5WPTNSVeg5/HkABRG0GVRydXRoTW9uZ2VyIDx0
bUBkZXYubnVsbD6JARUDBRAzgptRPTNSVeg5/HkBAXUeB/4y3/VlUzua8TVbAiTW
KPXvqTq28XHrhNrTiDWXX7KaFmRyZC20OLbRNtJH1XJUeZv7yhxXkIO2jW6e1i95
MWcx0JAheNjdqKAdNFUVaqs6R2+ySAU7PtfbfVx/RUxsTW8jLfppI7ajTf3E9z3u
nO6NpN/z74DO659tiwfNjT8YoRH3EEomSKNZ3yIGhbyTHv+FOrJs8sQ3jhqmFb37
nr0er1+BWi9Sr2LS7aK+iCK/ZKhUqaofkoo6S/M6nTWKU7RiDhvK0wm40Lassb83
z3NjwN2NNZDwCPYM3d12LjxWA70qljx/qsSRptvkDmnLKXnEUvTsnf9dErhpYLtg
yGBFiQCVAwUQM4LW/7BfjJBm+4xlAQEbJAP/RsKZ/khOS+4nD7JfPnKMKMVjDOif
x0enjzf7kW//GnMsi70yaYi6QeoT0YUYVNQ+wWwGUPgAejs2PLk1VIbn4GIvRU+1
Uj6xTTfHkIibUtvz7LtC/JmNafWSETDnJOlqszgzTnE0duDwZ83ISWdzHkhEXnfC
BxcPay75u1zC6FQ=
=j6da
-----END PGP PUBLIC KEY BLOCK-----