Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Clarification on Encryption Export Using CKE
From: Nicolas . Graner @ cri . u-psud . fr (Nicolas.GRANER)
Date: Mon, 25 Mar 1996 15:26:46 --100
To: firewalls-digest @ GreatCircle . COM
In-reply-to: "thompson @ tis . com"'s message of Fri, 22 Mar 1996 10:13:58 -0700

> All that occurs additionally is that a Data
> Recovery Field (DRF) is created for the user and each receiver (each
> firewall in a Global Virtual Private Network) in stronger cryptography than
> the message itself.  The DRF contains this same session key and a unique
> user identifier, all encrypted with the public key of a Data Recovery
> Center (DRC).  The DRF is tagged with a plaintext identifier for the DRC.
> It is NEVER sent to the DRC.

I am missing something here. What prevents the sender from filling in
the DRF with random gibberish? Nobody would ever know until someone
tries to recover the key. If you allow me to import your system
outside the US, I will give it a false DRC public key, and the system
will work just fine, except the CIA won't be able to "recover" my
message. I don't see why politely asking terrorists to encrypt their
keys into every message will satisfy the US government's goals.

What am I missing?

Nicolas Graner
CRI - Batiment 211                 Telephone : +33/1/69 41 61 06
Universite de Paris-Sud            Fax :       +33/1/69 41 69 86
91405 Orsay Cedex                  Email :     Nicolas .
 Graner @
 cri .
 u-psud .
 fr
France

Indexed By Date Previous: Re: Sick Puppy
From: "Jonathan M. Bresler" <m1jmb00 @ FRB . GOV>
Next: FW: DOS firewalls
From: "william.wells" <william . wells @ damark . com>
Indexed By Thread Previous: Re: Clarification on Encryption Export Using CKE
From: Adam Shostack <adam @ homeport . org>
Next: Re: Clarification on Encryption Export Using CKE
From: thompson @ tis . com (Bill Thompson)

Google
 
Search Internet Search www.greatcircle.com