Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure I understand what you mean by PGP not requiring SHA-1's cryptographic properties. Do you mean that PGP's authenticated encryption mode only requires preimage resistance?


Not even that. It only requires that the hash is not reversible.


Can you elaborate? This doesn't match my understanding of how "authenticated" encryption works in PGP (by which I assume you mean MDC, which is closer to integrity-without-identity than authentication).


For most PGP use, the MDC only serves as an integrity check [1]. That is the same for the proposed modes as well. In the case of symmetrical encryption it does in fact serve to authenticate the encrypted material based on the passphrase.

It does not use the popular combination of an encryption function acting more or less independently of a MAC (message authentication code). It uses a different method[2]. This seems to cause much confusion.

[1] https://articles.59.ca/doku.php?id=pgpfan:authenticated

[2] https://articles.59.ca/doku.php?id=pgpfan:mdc




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: