correction, Re: HushMail interoperability

David Shaw dshaw@jabberwocky.com
Fri Sep 6 08:47:02 2002


On Wed, Sep 04, 2002 at 09:48:52AM +0200, David Pic=F3n =C1lvarez wrote:
> I've desinstalled Sun's java and now the applet works so I have submitt=
ed my
> public key and got the public key from my correspondant.
>=20
> But I would like to know what mdc is for since I usually use automatic
> encryption and if I have to use this switch only with this person it wo=
uld
> make my life slightly more difficult.

The MDC is essentially a hash of the document, encrypted along with
the document.  Think of it as a mini-signature to verify that the
document was not tampered with in transit.

It prevents some attacks against a message that involve such
tampering.  Admittedly, those attacks are extremely difficult to pull
off.  You can read http://www.counterpane.com/pgp-attack.html for all
the details.

David

--=20
   David Shaw  |  dshaw@jabberwocky.com  |  WWW http://www.jabberwocky.co=
m/
+------------------------------------------------------------------------=
---+
   "There are two major products that come out of Berkeley: LSD and UNIX.
      We don't believe this to be a coincidence." - Jeremy S. Anderson