Updated: 24.11.2002; 12:36:06 Uhr.
disLEXia
lies, laws, legal research, crime and the internet
        

Thursday, July 26, 2001

Microsoft's PGP keys don't verify

[From Dave Farber's IP, archived at http://www.interesting-people.org/ Submitted by Ben Laurie, who commented that As the immortal phrase has it, "the RISKS are obvious." PGN]

FYI ...

Microsoft Bulletins Fail PGP Verification http://www.newsbytes.com/news/01/168397.html

For at least four months, Microsoft has been sending out security bulletins which fail a popular e-mail authentication system. As a result, the company could be opening the door to counterfeit bulletins from malicious hackers.

To protect against forgery, Microsoft's security response center digitally signs its bulletins with PGP before e-mailing them to subscribers of its security notification service. But since at least March, if recipients attempt to verify the messages' authenticity, PGP will issue a warning that the bulletins contain an invalid signature.

"The problem is that Microsoft's bulletins effectively look as if they're forged. And telling a Microsoft forgery from someone else's is virtually impossible," said Paul Murphy, head of information technology at Gemini Genomics, a genetic research firm in Cambridge, England. [...] [Brian McWilliams via risks-digest Volume 21, Issue 56]
0:00 # G!


Maximillian Dornseif, 2002.
 
July 2001
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31        
Jun   Aug

Search


Subsections of this WebLog


Subscribe to "disLEXia" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.