1993-08-26 - Re: Commercial PGP: Verifying Trustworthiness

Header Data

From: peter honeyman <honey@citi.umich.edu>
To: cypherpunks@toad.com
Message Hash: d09f5cc94d554c5c0ee9a039af452ea38eceb0e09d1e029f3512a28c41067b82
Message ID: <9308261825.AA25232@toad.com>
Reply To: N/A
UTC Datetime: 1993-08-26 18:25:47 UTC
Raw Date: Thu, 26 Aug 93 11:25:47 PDT

Raw message

From: peter honeyman <honey@citi.umich.edu>
Date: Thu, 26 Aug 93 11:25:47 PDT
To: cypherpunks@toad.com
Subject: Re: Commercial PGP: Verifying Trustworthiness
Message-ID: <9308261825.AA25232@toad.com>
MIME-Version: 1.0
Content-Type: text/plain


> Basically, if both commercial PGP and freeware PGP produce exactly the
> same encrypted files as output based on the same keys, and if you have
> the source code and can trust freeware PGP, then it can be stated that
> commercial PGP is secure.  

pgp and viacrypt will always generate differnt outputs: pgp
adds some pseudo-random stuff to the start of the file it is
encrypting to ensure that a file encrypts differently each time. 

	peter





Thread