Justin J O'Brien
2014-01-01 01:01:03 UTC
I know how to use a PGP key to verify a signature (in Debian, if it makes any difference), but I hardly know anything about how or why it works. Recently I decided to do a little experiment, and the result made me worry – but I don't know whether there's really anything to be worried about, so I'm seeking the guidance of those who know more than I. I will be extremely grateful for any assistance.
My experiment was that I opened a particular public key in a text editor, changed a few characters (I didn't document exactly what I changed but it was about 5 or 10 characters not very close to the beginning or end), saved it, and then tried to use it to verify the signature of a particular file (of course, this file had been signed with the private key corresponding to the public key that I modified). I deleted all the keys in my keyring before importing the modified key. When I tried to verify the signature, it said the signature was good. This seemed like a red flag to me, since I'd expected that the changes I'd made would make the key unable to correctly decrypt the signature. Is this suspicious? Or is it to be expected that the signing key would still work after I changed a few characters in a text editor? My first thought was that my system may have been altered so that it says bad signatures are actually good (I have a stalker so this is not
outside the realm of possibility). Should I be worried?
------------------------------------
______________________________________________________________
Archives: http://groups.yahoo.com/group/PGP-Basics/messages
OT List: http://groups.yahoo.com/group/PGP-Basics-OT
OT Subscribe: mailto:PGP-Basics-OT-***@yahoogroups.com
Gossamer Spider Web of Trust http://www.gswot.org
Yahoo Groups Links
<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/PGP-Basics/
<*> Your email settings:
Individual Email | Traditional
<*> To change settings online go to:
http://groups.yahoo.com/group/PGP-Basics/join
(Yahoo! ID required)
<*> To change settings via email:
PGP-Basics-***@yahoogroups.com
PGP-Basics-***@yahoogroups.com
<*> To unsubscribe from this group, send an email to:
PGP-Basics-***@yahoogroups.com
<*> Your use of Yahoo Groups is subject to:
http://info.yahoo.com/legal/us/yahoo/utos/terms/
My experiment was that I opened a particular public key in a text editor, changed a few characters (I didn't document exactly what I changed but it was about 5 or 10 characters not very close to the beginning or end), saved it, and then tried to use it to verify the signature of a particular file (of course, this file had been signed with the private key corresponding to the public key that I modified). I deleted all the keys in my keyring before importing the modified key. When I tried to verify the signature, it said the signature was good. This seemed like a red flag to me, since I'd expected that the changes I'd made would make the key unable to correctly decrypt the signature. Is this suspicious? Or is it to be expected that the signing key would still work after I changed a few characters in a text editor? My first thought was that my system may have been altered so that it says bad signatures are actually good (I have a stalker so this is not
outside the realm of possibility). Should I be worried?
------------------------------------
______________________________________________________________
Archives: http://groups.yahoo.com/group/PGP-Basics/messages
OT List: http://groups.yahoo.com/group/PGP-Basics-OT
OT Subscribe: mailto:PGP-Basics-OT-***@yahoogroups.com
Gossamer Spider Web of Trust http://www.gswot.org
Yahoo Groups Links
<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/PGP-Basics/
<*> Your email settings:
Individual Email | Traditional
<*> To change settings online go to:
http://groups.yahoo.com/group/PGP-Basics/join
(Yahoo! ID required)
<*> To change settings via email:
PGP-Basics-***@yahoogroups.com
PGP-Basics-***@yahoogroups.com
<*> To unsubscribe from this group, send an email to:
PGP-Basics-***@yahoogroups.com
<*> Your use of Yahoo Groups is subject to:
http://info.yahoo.com/legal/us/yahoo/utos/terms/