August 12, 2002 8:30 AM PDT

PGP defect reveals encrypted messages

update Messages encrypted with the Pretty Good Privacy algorithm could fall prey to a technique that fools senders into decoding their own secret messages, according to researchers.

The attack is known to work against the widely used open-source encryption software GNU Privacy Guard, but requires that the would-be spy first intercept the message and then convince the sender to decrypt what seems to be a second message.

A noted cryptographer, however, stressed that PGP is not broken.

"If I use this, I get one message--I don't get your (secret) key," said Bruce Schneier, founder and chief technology officer of network protection provider Counterpane Internet Security. Schneier proved the existence of the flaw with Jonathan Katz, a professor at the University of Maryland at College Park, and with one of Katz's graduate students.

Details of the attack method will be given at a lecture at the Information Security Conference in Sao Paulo, Brazil, later this year, and paper on the attack method is available now at the Counterpane site.

The attack takes advantage of a flaw that existed in the PGP standard until last year. Because the defense against the attack requires that developers break compatibility with older versions, the makers of many encryption programs haven't fixed the problem.

That's the case with GnuPG, said Jon Callas, principal author of the OpenPGP formats standard for the Internet Engineering Task Force, the group responsible for setting technical standards on the Internet.

"Schneier and Katz have come up with a practical attack against this weakness that we have known about for a while," he said. "It's mainly a con attack--one person has to convince another to do something."

PGP is an example of a public-key encryption system. Each person using PGP has a private key, which they keep secret, and a public key, which they publish. A message encrypted with the public key can be decrypted by the private key, and vice versa.

The attack can be described using the typical cast of encryption problems: a sender (Alice), a receiver (Bob) and an eavesdropper (Eve). When Alice wants to send Bob a message, she encrypts the plaintext of her message with Bob's public key. No one can decrypt the message except for Bob, but Eve does manage to intercept the message.

Deciding that she wants to figure out what the message says, Eve applies a specific set of mathematical functions to the so-called ciphertext, corrupting it. Eve then sends the corrupted message, essentially a damaged version of Alice's encrypted message, to Bob without encrypting it. Bob decrypts it with his public key and gets a lot of garbage. Puzzled, Bob contacts Eve, who asks Bob to send the garbage text back. Eve then reverses the mathematical functions and removes the corruption from the message, and is left with the original message that Alice sent.

The mathematical sleight of hand is possible because there is a specific class of mathematical function that can be applied to an encrypted message and can be removed after the message is decrypted. Known as a homomorphism, the flaw opens the door to social-engineering attacks--that is, those that trick humans rather than break a code directly.

"The moral is not to send gibberish back to the person you got it from," said Schneier. "You decrypted it and sent it back to me. Unbeknownst to you, you have decrypted the message, but because of the corruption, you don't know it."

In March, security company Network Associates dropped its support for the PGP software after it failed to find a buyer for its PGP business unit. Network Associates still owns the intellectual property surrounding the encryption, which it bought from PGP's creator, Philip Zimmermann.

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    At the TechCrunch50, an unfair advantage?

    Inside baseball: How Webware and other blogs can compete with TechCrunch in covering the TechCrunch50 event.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.