[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: GAK/CDR workarounds



At 08:35 27.10.97 +0000,  Lindsay Mathieson wrote:
>PMJI, but to me, there seems to be a very simple fix for users, if they wish
>to prevent their messages being decrypted by third-parties.
>
>When replying with a GAK/CDR compliant applictaion, it would seem reasonably
>easy to encrypt the message twice, i.e. embed a standard PGP encrypted
>message inside a GAK/CDR encrypted message. Your recipent can decrypt it
>with their private key, while the thirdy party receives a standard PGP
>encrypted message.
>

As far as I know, this is just the problem, because PGP 5.5 forces you to
encrypt with your key and the corporate key. 

Or is it possible to work around the GAK as stated above ?

If it is, would not future GAK-encryption software deny encryption of
preencrypted messages ? Or even worse demand messages to be send in special
formats which can not be altered or mailing would be denied altogether.

Regards,

George