[Spooks] kinda a spooky question

William Knowles [email protected]
Mon, 25 Mar 2002 19:16:49 -0600 (CST)


On Mon, 25 Mar 2002, blitz wrote:

I'll be quick on this since its off-topic...

> I figured this group would know this.
> Ive been in a discussion about PGP encryption on another list.
> 
> There is some concern that PGP 7.0.3 had been compromised, compared
> to 6.5.8, actually ANY PGP above 6.5.8

The last copy of source code available that has been through a peer
review is 6.5.8, and I should add that is done by civilian
cryptographers and not seasoned professionals.

The truly paranoid that I deal with, only use PGP 2.3 since that was 
the last version to come out before all the charges were dropped on 
Phil and some suspect the backdoor was added to PGP 2.6.2. and all 
future versions of PGP.

Lastly, its called Pretty Good Privacy, and in the words of an old 
military cryptographer whose name I have conveniently forgotten. :)

"Never trust any cryptosystem that has been developed be someone who 
hasn't spent a considerable amount of time doing cryptoanalysis on 
other crypto schemes!"
 
Cheers!

William Knowles
[email protected]



*==============================================================*
"Communications without intelligence is noise;  Intelligence
without communications is irrelevant." Gen Alfred. M. Gray, USMC
================================================================
C4I.org - Computer Security, & Intelligence - http://www.c4i.org
*==============================================================*