GnuPG 2.1.0 "modern" released
GnuPG 2.1.0 "modern" released
Posted Nov 13, 2014 18:28 UTC (Thu) by epa (subscriber, #39769)In reply to: GnuPG 2.1.0 "modern" released by dkg
Parent article: GnuPG 2.1.0 "modern" released
First: the issue isn't whether some arbitrary LWN commenter has the time, resources, and skills to mount such an attack (though i agree if they can, that's really bad for the digest). The problem is whether a dedicated adversary has the time, resources, and skills.It really depends on your application. A dedicated adversary has the ability to tap my phone line, but that does not stop me personally from using telephone banking. Others will have more stringent requirements. There certainly is value in cryptography which is strong enough to stop any adversary short of a dedicated supercomputer-backed attack by Mossad or whatever your preferred fantasy scenario is. At that point, the weak link in the chain will not be the cryptography.
GPG doesn't know what the user's requirements are and isn't in a position to judge whether MD5 is strong enough. You suggest that if the tool cannot provide a strong assurance it should not support any checking. But there might be practical attacks against SHA256 being executed right now by NSA cryptographers, just that we don't know about them. It is not possible for GPG or any other program to provide any "assurance" about cryptographic strength now or in the future. Or, to reuse a catchphrase from elsewhere: mechanism, not policy. It is the user's policy decision which ciphers and hash functions to accept as secure enough, and GPG's job to check what it is asked to check. (Of course it would be a good idea to ship GPG with a default policy requiring strong ciphers and key lengths; nobody wants to go back to the bad old days when PGP's default configuration generated crappy keypairs. But in the end it is the user's choice to override that if wanted.)
On the other hand, if what you say is correct, and it should just drop support for hash functions which it can't provide any assurance for, then that would apply just as well to the historic branch of GPG. Support for the older keys should be removed from 1.4 also. Or if there is a reason for 1.4 to exist and a reason for it to continue supporting the older keys, perhaps that's because there is a legitimate need to keep using these older cryptographic mechanisms, for all that they may be breakable by some possible adversary?
