Discussion:
Signing with PGP in USenet
(too old to reply)
Ukain
2008-09-19 14:05:12 UTC
Permalink
Is it possible to copy and paste the GPG signature on a Usenet message
and for this to be verified normally?

The idea is to copy the GnuPG signature to the clipboard and from then
paste it on my newsreader messages I am not sure if this works fine.

Thank you
Neil - Salem, MA USA
2008-09-19 15:03:25 UTC
Permalink
Is it possible to copy and paste the GPG signature on a Usenet message and
for this to be verified normally?
The idea is to copy the GnuPG signature to the clipboard and from then
paste it on my newsreader messages I am not sure if this works fine.
Thank you
I'm guessing that you mean the following:

1) You cut a valid signature from someone's Usenet message
2) You compose a message of your own and then
paste the signature to the end of this new message
3) The signature verifies correctly (you wonder)

If what I have just described is what you mean, the no, this will not work.
The signature will not verify and a warning message will be displayed.

Note that the signature is a mathematical hash
(http://en.wikipedia.org/wiki/Cryptographic_hash_function) of the content of
the message and is created from the message and from the private key of the
author of the message. Verifying the signature requires the reader to have
PGP/GPG plus the message plus the author's public key.

Neil - Salem, MA USA
Neil W Rickert
2008-09-19 16:06:14 UTC
Permalink
Post by Ukain
Is it possible to copy and paste the GPG signature on a Usenet message
and for this to be verified normally?
The idea is to copy the GnuPG signature to the clipboard and from then
paste it on my newsreader messages I am not sure if this works fine.
If you are trying to sign a message that way, then you need to copy
the entire content of the clipboard (message plus signature) to
replace to original unsigned version of the message.
David E. Ross
2008-09-19 17:05:45 UTC
Permalink
Post by Ukain
Is it possible to copy and paste the GPG signature on a Usenet message
and for this to be verified normally?
The idea is to copy the GnuPG signature to the clipboard and from then
paste it on my newsreader messages I am not sure if this works fine.
Thank you
Even if the signature is actually your own, this will not work. A new,
distinct signature is generated not only for each distinct message but
also for the same message if you decide to generate it again. I just
now signed the same file twice and got two different signatures.

Remember, a signature not only authenticates the source (providing you
have verified the identity of the person who controls the private key
used for signing) but also assures integrity of the message. This
latter happens when the slightest change in the message invalidates the
signature. Thus, each distinct message has a distinct signature.
--
David E. Ross
<http://www.rossde.com/>

Q: What's a President Bush cocktail?
A: Business on the rocks.
Christoph Burschka
2008-10-11 14:23:46 UTC
Permalink
Post by David E. Ross
Even if the signature is actually your own, this will not work. A new,
distinct signature is generated not only for each distinct message but
also for the same message if you decide to generate it again. I just
now signed the same file twice and got two different signatures.
That's because the signature includes a timestamp. I'm not sure if two
signatures generated with precisely the same timestamp would also vary, but it
would be impractical to test...
--
"Omniscient? No, not I; but well-informed."
----------------------
XMPP: ***@gmail.com
AOL: 313125838 / cburschka
Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x55A52A2A
Loading...