[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Sheflug] Re: Re: GPG/crypto (was SUID bit)



Chris

Chris J/#6 wrote:

> This is all very well to say, but I have yet to see some references to back
> this up. There's a lot of conspiracy theories floating out out there, some of

I'm not going on about theoretical things.  I'm going on about
personal experience.  By that I mean having to live through the last
thirty years of mind blowing repression from both ends of the Atlantic
as well as Eastern Europe.

> which may be true, others not. I have the GnuPG source (for 1.0.2), and >there is *no* documentation within it that talks about crypto generally that >I can see, and has been pointed out that algorithms it uses includes 3DES and
>Blowfish. I have not found an archive of the GPG list - if you know of one, I
> will review it. I have posted references here, yet I am waiting for
> references from yourself, short of "GPG docs and GPG list", which isn't that
> precise.

It's generally assumed in the crypto circles that you have already had
at least ten years experience before you begin to learn more.  At
least, the people in the States seem to think that way.  This may not
be helpful but that's the way it is.

> Surely if they are classed as insecure, why would GPG implement
> them, based on what you have been saying?

Because part of the GNU thing is to fit in with the American legal
system and to agree with that is to give out to their own government. 
It's also true that people like Richard Stallamn believe in arguing
with their own government.  But, he is severely hampered by his own
system's way of doing things.

> Blowfish has been analysed and there is no known attack against it short of >a differential attack against weak keys. Twofish was, as has been pointed >out,

There's an old army joke which goes something like this.......

Blowfish is something that you can use between the wives legs when you
are a bit tired  [you know how it is ? All those assault courses ?]
 
Twofish is something that you can use on your wife and mistress at the
same time.

> For this, I fear we may have to aggree to disaggree.

Well, myself and the rest of the planet will disagree with you.  You
ought to get onto one or two crypto lists and see what you get thrown
at you ?

Thanks

-- 
Richard
Sheffield UK

---------------------------------------------------------------------
Sheffield Linux User's Group - http://www.sheflug.co.uk
To unsubscribe from this list send mail to
- <sheflug-request [at] vuw.ac.nz> - with the word 
 "unsubscribe" in the body of the message. 

  GNU the choice of a complete generation.