1995-09-13

From: Yih-Chun Hu <yihchun@u.washington.edu>
To: Andy Brown <asb@nexor.co.uk>
UTC Datetime: 1995-09-13 17:21:27 UTC
Raw Date: Wed, 13 Sep 95 10:21:27 PDT

From: Yih-Chun Hu <yihchun@u.washington.edu>
Date: Wed, 13 Sep 95 10:21:27 PDT
To: Andy Brown <asb@nexor.co.uk>
Subject: Re: Scientology tries to break PGP - and
Content-Type: text/plain

On Wed, 13 Sep 1995, Andy Brown wrote:

> On Wed, 13 Sep 1995, Henry W. Farkas wrote:
> > If decrypted with the "alternate" or "fake" secret key, the encrypted file
> > is wiped until it reaches a marker; the remainder of the file is
> > displayed.  If you use your "primary" or "real key", the extraneous text
> > is simply stripped.
> Useless I'm afraid.  They have the source code and have disabled your
> "feature" and attached loud alarm bells to it.

I don't see whats wrong with removing any checking done by PGP.
(ie don't keep a checksum or whatever) After all, they can't prove
that you didn't just encrypt a pgp +makerandom file.

Obviously, I would not want to use this "feature" in some cases,
so make adding a checksum be an extra command line option.

The new feature would of course not be backwards compatible, but
there is no way to disable the "feature" and no way to attach
loud alarm bells.

Of course, you are then faced with giving them a key which you know
will decrypt the file to gibberish. Ideally, you would steno the 
encrypted file.

