[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Decision: Encryption Method/Product



See comments below...Rik

Robert Moskowitz, wrote:
>
.....Parts deleted ....................
>
>But the biggest concern I have of the strength of S/MIME is the presence of
>any known text.  All of those imbedded MIME headers.  This is exactly the
>attack that got Microsoft's WFW .pwl files!  (If you know that starting in
>position 10 you will find the string 'application', the crypto analysis is
>very easy).

Under these conditions, we will find it hard to encrypt ANY EDI data at
all, since the ISA (UNA) are well know structures with specific byte
offsets. Moving ISA information into the MIME heading fields may only make
this worse.


>
>The other problem with S/MIME is that it will tend to restrict product to
>those that can afford to pay RSA.
>
>Robert Moskowitz
>Chrysler Corporation
>(810) 758-8212

------------------------------------------------------
|         Rik Drummond - The Drummond Group         |
|   5008 Bentwood Ct., Ft. Worth, TX 76132 USA  |
|        Voice: 817 294 7339    Fax: 817 294 7950     |
------------------------------------------------------