ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

NA confirms PGP bug and promises a fix Friday

Graeme Wearden ZDNet.co.uk

Published: 25 Aug 2000 17:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security firm Network Associates (NAI) has promised a fix for versions 5.5.x to 6.5.3 of its PGP (Pretty Good Protection) encryption software.

The email systems contain a serious security bug discovered by Ralf Senderek, a German researcher. The vulnerability could allow an unauthorised third party to read encrypted emails rendering the software useless.

Senderek found that some PGP software cannot distinguish between a third-party encryption key that had been maliciously added to a public PGP key, and one placed with a user's consent. Some companies add such third-party encryption to their employee's emails so messages can be decoded if a member of staff leaves or for criminal investigations.

Phil Zimmermann, who created PGP, explained that fixing the bug was a top priority. "We at NAI/PGP were made away of this bug in PGP early this morning, and we're responding as fast as we can. We expect to have freeware and commercial patches released on Friday".

The PGP 6.5.x freeware release will be available from the MIT Web site, and commercial fixes for versions 5.5.x upwards will be posted on www.nai.com and www.pgp.com.

A PGP user has one public and one private encryption key. The public key is used to securely encrypt an email and is distributed within the public key certificate, either in a user's emails or on a public server or Web page. To decode an encrypted email, it is necessary to know the private key, which the user should keep secure.

Pressure from government bodies led to the creation of Additional Decryption Keys (ADKs), which are added to the public key certificate and allow a third party to also decrypt emails that were encrypted by the public key. If a user agrees to an ADK being added to his public key, it is placed within the secure area of the certificate.

Because public key certificates are widely available, it is simple to add an unauthorised ADK to the insecure. Senderek discovered that PGP versions 5.5.x to 6.5.3 fail to check whether an ADK has been placed within the secure area of a certificate. The implication is that if an unauthorised person could add their own ADK to a PGP certificate, they would then be able to read any emails encrypted using the modified public key.

Because an attacker would still have to intercept the victim's emails, some security experts believe it unlikely that this flaw has actually been taken advantage of. However, there is no way of knowing to what extent this is true.

They can see you... Read about how and why in Surveillance, a ZDNet News Special

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
27 out of 60 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Commercial Support Analyst

Led by a high performance management team, our IT team consists of innovative professionals working together to deliver IT solutions that provide a ...

Head of Central Applications

In return for your efforts, you can expect a competitive basic salary as well as a generous benefits package including, for example, pension scheme, ...

Systems Testing Manager

Led by a high performance management team, our IT team consists of innovative professionals working together to deliver IT solutions that provide a ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment