Dev Shed Lounge
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOtherDev Shed Lounge

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Dell PowerEdge Servers
  #1  
Old January 5th, 2002, 05:40 PM
Marky_Mark Marky_Mark is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2001
Location: On a screen near you
Posts: 498 Marky_Mark User rank is Private First Class (20 - 50 Reputation Level)Marky_Mark User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
PGP can anyone shed somelight

Can anyone shed somelight on this


I might seem a little naive here but here goes...


Someone sent me an email that was encrypted using PGP
and i was able to read it without knowing who it was from...


But i thought that if i was to read a PGP encrypted email i would need the PGP key and i havent exchanged keys with anyone


Im using Windows with Outlook and have a firewall but does anyone know if i been hacked or is it normal to be able to read PGP mail without exchanging keys, is it all transparently


Can someone explain... im confused


Mark
__________________
100 trillion calculations per nanosecond

Last edited by Marky_Mark : January 5th, 2002 at 05:46 PM.

Reply With Quote
  #2  
Old January 6th, 2002, 07:35 AM
Jonathon's Avatar
Jonathon Jonathon is offline
T-Shirt Tragic
Dev Shed Novice (500 - 999 posts)
 
Join Date: Mar 2001
Location: Melbourne, Australia
Posts: 812 Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Week 2 Days 19 h 46 m 5 sec
Reputation Power: 198
Send a message via Skype to Jonathon
was it actually encrypted or was it merely signed? Did you have to perform any sort of decryption action or was it all there in plain english with a little bit of PGP junk at the bottom?

Reply With Quote
  #3  
Old January 6th, 2002, 12:53 PM
Marky_Mark Marky_Mark is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2001
Location: On a screen near you
Posts: 498 Marky_Mark User rank is Private First Class (20 - 50 Reputation Level)Marky_Mark User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
The mail was PGP signed and readable it also had a PGP signature at the base of the message


It's just dawned on me...


Does PGP send the key with the message?


Mark

Reply With Quote
  #4  
Old January 6th, 2002, 01:13 PM
JMM JMM is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: Feb 2001
Location: USA
Posts: 830 JMM User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 h 17 m 56 sec
Reputation Power: 8
For someone to send you a PGP encrypted message that you would be able to decrypt, it would have to be encrypted with your public key.

Reply With Quote
  #5  
Old January 6th, 2002, 01:56 PM
Marky_Mark Marky_Mark is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2001
Location: On a screen near you
Posts: 498 Marky_Mark User rank is Private First Class (20 - 50 Reputation Level)Marky_Mark User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
Yeah but that doesn't answer my question


Mark

Reply With Quote
  #6  
Old January 6th, 2002, 05:25 PM
Jonathon's Avatar
Jonathon Jonathon is offline
T-Shirt Tragic
Dev Shed Novice (500 - 999 posts)
 
Join Date: Mar 2001
Location: Melbourne, Australia
Posts: 812 Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level)Jonathon User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Week 2 Days 19 h 46 m 5 sec
Reputation Power: 198
Send a message via Skype to Jonathon
It sounds to me like it was signed but not encrypted... PGP can be used to "sign" a message providing gaurantee that the author is who he says he is. The PGP junk at the bottom of the message is the key you can use to verify the authenticity.
Often you will find people post messages to public maillists and newsgroups that are signed but not encrypted .. this is so people who do not have PGP installed or do not have the senders public key can still read the message and those who do have the public key can verify the authenticity of the message.

part of the signature is mixed up with encrypted bits of the actual message so it's impossible to just copy someone's signature and stick it on a bogus message to forge identity...

this is what I get after verifying a message I've signed -

*** BEGIN PGP SIGNED MESSAGE ***

*** PGP Signature Status: good
*** Signer: Jonathon Wallen <z2213441@student.unsw.edu.au>
*** Signed: 7/1/02 at 10:10 AM
*** Verified: 7/1/02 at 10:10 AM

If I copy the signature into a different message (one that wasn't actually signed) I get this -

*** BEGIN PGP SIGNED MESSAGE ***

*** PGP Signature Status: bad signature
*** Signer: Jonathon Wallen <z2213441@student.unsw.edu.au>
*** Signed: 7/1/02 at 10:10 AM
*** Verified: 7/1/02 at 10:14 AM

Reply With Quote
  #7  
Old January 6th, 2002, 11:08 PM
Marky_Mark Marky_Mark is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2001
Location: On a screen near you
Posts: 498 Marky_Mark User rank is Private First Class (20 - 50 Reputation Level)Marky_Mark User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
Jonathon you were right


Thanks for the info



Mark

Reply With Quote
Reply

Viewing: Dev Shed ForumsOtherDev Shed Lounge > PGP can anyone shed somelight


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

 Free IT White Papers!
 
Accelerating Trading Partner Performance
One in five. That's how many partner transactions have at least one error. That is an amazing statistic, particularly given the extraordinary leaps in innovation across the global supply chain during the past two decades. Download this white paper to learn more.

 
Competing on Analytics
This Tech Analysis is designed to help identify characteristics shared by analytics competitors, and includes information about 32 organizations that have made a commitment to quantitative, fact-based analysis.

 
Cost Effective Scaling with Virtualization and Coyote Point Systems
An overview of the industry trend toward virtualization, how server consolidation has increased the importance of application uptime and the steps being taken to integrate load balancing technology with virtualized servers.

 
Five Checkpoints to Implementing IP Telephony
Implementation planning for IP PBX software and IP telephony has become vital as businesses replace discontinued legacy PBX phone systems. This informative whitepaper outlines five "checkpoints" for any implementation plan that will help make IP communications a successful proposition.

 
Hosted Email Security: Staying Ahead of New Threats
In the last two years, email has become a fierce battleground between the nefarious forces of spam and malware, and the heroes of messaging protection. The spam volumes increased alarmingly every month, bringing clever new forms of phishing and virus propagation attacks.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway