you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 1 week ago (5 children)

Alright, so just because a plain text signature is along with content, doesn't mean that the content is signed.
Then how do you check that the content is signed by the plain-text signature given with it?

I thought that the signature means that either a whole copy of the text is encrypted or a hash of the text is encrypted using the private key, which would mean that spoofing the sign would require solving complexity equal to either of:

  • Finding another string that gives the same hash
  • Finding the private key and signing a new hash with it

What am I missing?

  • source
  • hideshow 5 child comments
  • [–] 3 points 1 week ago (4 children)
  • [–] 1 point 1 day ago (2 children)

    The above question came to me after watching the video.
    IDK maybe I just have low IQ.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 day ago (1 child)

    Might be slop then. I didn't watch the video.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 15 hours ago

    Well they did leave out a lot of important information.

    This site seems pretty good though: https://gpg.fail/
    It has all the given vulnerabilities in text.

    Now just need to read and understand all of them and find out which one explains the above comment and the answer to my question is probably another headache.

  • source
  • parent
  • [–] 4 points 5 days ago* (last edited 5 days ago)

    That was what I prefer to read instead, but fine

    Edit: I did watch it, they don't even tell, because it was in the previous disclosure, so I now need to find and watch that one

    Edit2: and from reading https://gpg.fail/ with original vulnerability descriptions I can't understand how they did the trick with ISO, is the ISO signed as if it were plaintext and allowed truncated lines? If so, this does look pretty bad both on implementation side and on user side, imo

  • source
  • parent