GnuPG 2.1.0 "modern" released
GnuPG 2.1.0 "modern" released
Posted Nov 13, 2014 16:01 UTC (Thu) by epa (subscriber, #39769)In reply to: GnuPG 2.1.0 "modern" released by dd9jn
Parent article: GnuPG 2.1.0 "modern" released
We all agree that MD5 is less than ideal because there have been some successful research efforts to find weaknesses in it. We all agree that at some point in the future it is likely that further flaws will be found, and/or advances in CPU power will make a brute force attack possible using the existing known weaknesses.
What doesn't make sense is to deduce from that that existing MD5 signatures (or keys which use MD5, etc) are so broken they are not worth supporting for existing documents. Existing signed and encrypted messages exist in many people's inboxes. For better or worse electronic mail and saved mailboxes are used as a permanent archive and record of what people said. Some of those messages will be from people who are no longer alive, or who for whatever other reason refuse to re-sign older messages with whatever is today's recommended system.
If you feel that "signed mails should be considered unsigned" then I invite you to take a message signed with an older key and produce a forgery with the same signature. (No, not a block of random data but an even remotely plausible forged message.)
