You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Messages without authentication tags (called MDC by OpenPGP) can be modified by an attacker. Malleable plaintexts lead to all sorts of attacks, the latest example being EFail.
The spec is hopelessly broken in therms of downgrade protection, so a message originating with a MDC can be stripped to look like a normal message without MDC. So the only fix is to disable support for MDC-less messages entirely.
Also, MDC were added in 2001, and it's 2018.
The text was updated successfully, but these errors were encountered:
Messages without authentication tags (called MDC by OpenPGP) can be modified by an attacker. Malleable plaintexts lead to all sorts of attacks, the latest example being EFail.
The spec is hopelessly broken in therms of downgrade protection, so a message originating with a MDC can be stripped to look like a normal message without MDC. So the only fix is to disable support for MDC-less messages entirely.
Also, MDC were added in 2001, and it's 2018.
The text was updated successfully, but these errors were encountered: