Feeds

PGP, GPG defeated

Not broken, just beaten

  • alert
  • submit to reddit

Internet Security Threat Report 2014

OpenPGP and GnuPG are susceptible to a chosen-cyphertext attack which would allow an adversary capable of intercepting an encrypted message to use the intended recipient as an unwitting 'decryption oracle', researchers Kahil Jallad, Jonathan Katz and Bruce Schneier report in a recent paper.

In a nutshell, Jane sends an encrypted e-mail message to Dick. Unfortunately, Bill intercepts Jane's message and forwards her message to Dick following a bit of tinkering. When Dick receives it, he's puzzled by an incomprehensible message. If he replies to Bill for clarification with the cyphertext in his reply, and if he has his crypto program set on cruise control, Bill may well be able to read Jane's message.

Of course there are numerous complications which we'll get to presently, but conceptually that's all there is to it. It's similar to a man-in-the-middle attack, only Dick and Jane are not kept under the illusion that they're communicating with each other.

The authors have confirmed that the attack can be exploited practically.

However, it's not exactly easy. One obstacle for the attacker, Bill, is to tempt Dick into replying. If they're already acquainted, this should be easy. If they're strangers, then a bit of social engineering will be in order. The most obvious point of failure, then, is the problem of causing Dick to take action.

On the technical front, there are a number of conditions which have to be met for the attack to succeed. First, Dick has to set his PGP or GPG application to encrypt automatically, or somehow choose to encrypt a reply to what appears to be a nonsense message. Second, if he uses the crypto application's compression feature (which is normal) the attack will fail. With GPG it fails because of an integrity check which is not actually required by the standard, but which is widely employed. With PGP it fails because, while the standard requires that 'uncompressed' be a valid condition, no one follows the requirement.

If Dick's reply is not compressed by the crypto app, but is compressed with an outside application, the attack will succeed.

What this example shows is that the standard is wrong and that the attack is unlikely in the real world merely because the rules are not being followed. The team recommends, obviously, that the standard be modified to protect against this sort of attack. It also illustrates the importance of a holistic approach to crypto applications.

It's not enough that an algorithm is strong. As we reported recently, a buffer overflow vulnerability in Network Associates' PGP plugin for MS Outlook on Windows was capable of compromising the user's privacy, and even of giving up his machine. In this case, too, there was no 'breaking' of the algorithm. It was simply an attack against a component of a crypto application, which in practical terms is just as bad.

The research team's paper describes the chosen-cyphertext attack in gruesome detail, parts of which, I readily confess, went in one eye and out the other as I read it. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
Sway: Microsoft's new Office app doesn't have an Undo function
Content aggregation, meet the workplace ... oh
Sign off my IT project or I’ll PHONE your MUM
Honestly, it’s a piece of piss
Return of the Jedi – Apache reclaims web server crown
.london, .hamburg and .公司 - that's .com in Chinese - storm the web server charts
NetWare sales revive in China thanks to that man Snowden
If it ain't Microsoft, it's in fashion behind the Great Firewall
Chrome 38's new HTML tag support makes fatties FIT and SKINNIER
First browser to protect networks' bandwith using official spec
Admins! Never mind POODLE, there're NEW OpenSSL bugs to splat
Four new patches for open-source crypto libraries
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.