Defeating MITM with Eric's Secure Phone

Anonymous anon at anon.efga.org
Thu Oct 9 20:33:59 PDT 1997



-----BEGIN PGP SIGNED MESSAGE-----

My apologies if this has already been discussed, but wouldn't this be
a straightforward solution?

Alice and Bob use PGP as a secure, identified channel to exchange a
random 6 digit hex number.  For example, 0xC926D0.

When they establish their Comsec connection, they read 0x5F92E4 off
their units.

Alice takes the digits C, 9, and 2, and adds them mod 16 to 5, F, and
9 to get the digits 1, 8, and B, which she reads to Bob who confirms
them.  (Adding just the digits instead of larger numbers means that
Alice and Bob can do the computation in their heads.)

Bob takes the digits 6, D, and 0 and adds them mod 16 to the digits 2,
E, and 4 to get 8, B, and 4.  Bob reads them to Alice who confirms
them.

Any flaws?

Monty Cantsin
Editor in Chief
Smile Magazine
http://www.neoism.org/squares/smile_index.html
http://www.neoism.org/squares/cantsin_10.html

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQEVAwUBND2EZ5aWtjSmRH/5AQGBnQf/QRMe/66ge+M/zHzzrZ7zc3g9wFKESsjA
alzeGfUulzp+18JyUy1RHNOtM+4bXZUaiYAN7FnxKkAkY+IzW5m7nDHMnC18e+bD
IZpO626Ze+pumokhXVTYW0JHWF4OfCol4qmYNSTjM+n4RO0DcmecOuQYuwnscJvb
808rsuin09dhY3UV5uyDWrCwuATIRjwSRTewBinuTGZo/QtMurXJlPc45WtF07oC
9Tg3ebnnq0NtbxWmsX7WT/tjFHoniS5sPoBusrlZT+1z+PT0SzqtSR1JmWKGVQQC
xubaghabXvNj9nZZPsEGCG4rMbJw8Qtoh9J6I+aQJ0TVK4hHuanJXw==
=Ooh/
-----END PGP SIGNATURE-----










More information about the cypherpunks-legacy mailing list