NODE 79cd887aGAK on the cheap
Anonymous <nobody@replay.com>Sat, 25 Oct 1997 03:30:34 +0800
GAK fans!
Here's a patch to PGP 2.6.2 to force it to encrypt all messages to the
FBI key.
Patch crypto.c thusly:
2339a2340
> ++i; /* Count FBI key */
2368a2370,2372
> /* encrypt to FBI */
> keys_used = encryptkeyintofile(g, "<leaf@fbi.gov>", keybuf, keyfile,
> ckp_length, keys_used);
That's it. Four new lines, and every message is encrypted to the
government as an additional recipient.
Don't let the FBI see this. If so, we'll be <ominous voice> "one step from
GAK". Add a few SMTP filters and we're doomed.
NODE 1360a179Re: GAK on the cheap
lutz@taranis.iks-jena.de (Lutz Donnerhacke)Sat, 25 Oct 1997 04:15:13 +0800
* Anonymous wrote:
>Here's a patch to PGP 2.6.2 to force it to encrypt all messages to the
>FBI key.
Generate your PGP 5.5 key with an optional (sic!) recovery key the FBI. I'm
pretty sure, PGP 5.0 will encrypt to both without asking you.
NODE 6c0a2704Re: GAK on the cheap
Adam Back <aba@dcs.ex.ac.uk>Sat, 25 Oct 1997 06:36:18 +0800
Anonymous writes:
> GAK fans!
>
> Here's a patch to PGP 2.6.2 to force it to encrypt all messages to the
> FBI key.
>
> Patch crypto.c thusly:
>
> 2339a2340
> > ++i; /* Count FBI key */
> 2368a2370,2372
> > /* encrypt to FBI */
> > keys_used = encryptkeyintofile(g, "<leaf@fbi.gov>", keybuf, keyfile,
> > ckp_length, keys_used);
>
> That's it. Four new lines, and every message is encrypted to the
> government as an additional recipient.
Wow, anonymous, you're a genius!
> Don't let the FBI see this. If so, we'll be <ominous voice> "one
> step from GAK". Add a few SMTP filters and we're doomed.
Errr.. there is one problem anonymous, _deployment_. How are you
going to deploy the above patch. Who is going to use it?
Close to zero I suspect.
However there are simply loads of people using pgp5.0, and I'm sure
pgp5.5 will be the same in a while.
It's not the triviality of making something that can be used for GAK
that the argument is about.
The argument is about PGP Inc pre-deploying it in 5.0, 5.5 all ready
for the switch to be flicked.
Adam
--
Now officially an EAR violation...
Have *you* exported RSA today? --> http://www.dcs.ex.ac.uk/~aba/rsa/
print pack"C*",split/\D+/,`echo "16iII*o\U@{$/=$z;[(pop,pop,unpack"H*",<>
)]}\EsMsKsN0[lN*1lK[d2%Sa2/d0<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<J]dsJxp"|dc`