He nāwaliwali ko ka hoʻopunipuni a PGP, ʻaʻole he leka uila i kahi ala paʻa o ka kamaʻilio

PGP

Nui nā manawa a mākou i ʻike ai, i kekahi ala a i ʻole ʻē aʻe, pehea ka palekana o ka pūnaewele. I kēia manawa, ʻo ka ʻoiaʻiʻo inā ʻo nā ʻoihana a me nā multinationals a puni ka honua, nā mea like i hilinaʻi ʻia e nā mea hoʻohana he nui, ua ʻike pehea i hiki ai i nā cybercriminal ke kiʻi i kā lākou mau kikowaena a ʻaihue i nā ʻōlelo huna a me nā ʻike pilikino o nā miliona o kā lākou mea hoʻohana, e noʻonoʻo i kēia hiki ke hana ʻia me nā noi ʻoi aku ka liʻiliʻi loa ma kahi, i nā manawa he nui, palekana i kahi backseat.

Ma mua loa o kēia mau mea, ʻo ka ʻoiaʻiʻo, a ʻoi aku ka pīhoihoi o kēia. nui nā kuʻina palekana, a hiki i kēia manawa me he mea lā palekana loa, e hoʻomaka nei e hāʻule. I kēia hanana ʻaʻole mākou e kamaʻilio e pili ana i kahi leka uila a i ʻole kahi ʻoihana me ka inoa a me ka inoa e hāʻawi iā ʻoe i kahi waihona leka uila, akā pili pono i nā kuʻina hana a kēia mau paepae paʻa, i hiki i kahi hui o nā kānaka noiʻi ke hiki e hōʻike i kāu mau leka uila i nā mea āpau me ka ʻike lawa.

ʻO ka PGP, ka kaho inoa hoʻopunipuni maʻamau no ka leka uila, kahi pilikino koʻikoʻi

Ke hele nei i kahi kikoʻī kikoʻī, e hoʻomaopopo iā ʻoe e kamaʻilio ana mākou e pili ana i nā kaohi palekana i kēia lā e hoʻohana ʻia e nā ʻoihana he nui e hoʻopunipuni a hāʻawi i kā lākou mea kūʻai aku i kahi lawelawe leka uila ʻoi aku ka paʻa. Kūleʻa mākou e kamaʻilio e pili ana Nā algorithms hoʻopunipuni PGP a i ʻole S / MIME, ʻo ia, e like me ka mea i ʻike ʻia, ʻeha ʻia mai kahi pilikino koʻikoʻi e hiki ai ke hōʻike i nā leka uila i hoʻopā ʻia i loko o ka plaintext, ʻo ia hoʻi nā leka āu i hoʻouna ai i ka wā i hala.

Ma kahi ala maʻalahi e hoʻomaopopo a kuhikuhi ʻana i nā huaʻōlelo o Sebastian schinzel, kekahi o nā loea palekana e hana nei ma kēia papahana a, a ʻo ka polopeka hoʻi o ka palekana kamepiula ma ke Kulanui o ʻEpekema ʻepekema ma Münster:

ʻO ka leka uila a me ka anus kahi ala paʻa o ka kamaʻilio

ʻO Electronica Frotier Foundation ke kuleana no ka lawe ʻana i ka mālamalama i kēia hemahema koʻikoʻi ma ka protocol PGP

E hāʻawi iā mākou i kahi manaʻo o ka pilikia, e haʻi iā ʻoe Ua ʻike mua ʻia kēia palupalu e ka Electronic Frontier Foundation i ke kakahiaka Pōʻakahi nei ma hope pono o kahi nūpepa Kelemania hoʻolaha nui i haki i kahi embargo nūhou. I ka manawa i hoʻolaha ākea ʻia ai kēia ʻike, ua hoʻomaka maoli ka hui o nā kānaka noiʻi ʻEulopa e pili ana i kēia ʻike e hoʻolaha i ka poʻe e hoʻōki i ka hoʻohana ʻana i nā algorithms hoʻopunipuni PGP a hiki i kēia lā, ʻaʻohe hopena kūpono e pili ana i ka nāwaliwali i ʻike ʻia.

E like me ka mea a nā kānaka noiʻi i ʻōlelo ai:

Hoʻoweliweli ʻo EFAIL i ka nāwaliwali ma nā kūlana OpenPGP a me S / MIME e hōʻike i nā leka uila i hoʻopā ʻia i ka huaʻōlelo maʻamau. E waiho wale, hoʻomāinoino ʻo EFAIL i ka ʻike i ka hana ma ka leka uila HTML, e like me nā kiʻi i hoʻoili ʻia i waho a i ʻole kaila, e kānana i nā hua ʻōlelo maʻalahi ma o nā URL i noi ʻia No ka hoʻokumu ʻana i kēia mau kahawai exfiltration, pono i ka mea hoʻouka kaua ke kiʻi i nā leka uila i hoʻopā ʻia, e laʻa me ke kāpae ʻana i ke kalepa pūnaewele, ka hōʻemi ʻana i nā helu leka uila, nā kikowaena leka uila, nā ʻōnaehana kākoʻo a i ʻole nā ​​kamepiula client. Ua ʻohiʻohi ʻia paha nā leka uila i nā makahiki i hala.

Hoʻololi ka mea hoʻouka i kahi leka uila i hoʻopilipili ʻia i kekahi ala a hoʻouna i kēia leka uila i hoʻopunipuni ʻia i ka mea i hōʻeha ʻia. Hoʻopiʻi ka mea leka uila a ka mea i hōʻino ʻia i ka leka uila a hoʻouka i nā ʻike kūwaho, exfiltrating the plaintext to the attacker.

He nui nā loea palekana e manaʻo nei ua hoʻonui ʻia kēia palupalu

E ʻike iki aʻe e pili ana PGP, haʻi iā ʻoe he mea ʻole ia ma mua o kahi polokalamu hoʻopunipuni, ma ka liʻiliʻi a hiki i kēia manawa, ua manaʻo ʻia ka hae no ka palekana leka uila. ʻO kēia ʻano leka uila i hoʻopā ʻia, no nā mea he nui i kēia mau lā i mea nui no kā lākou kamaʻilio ʻana, ua hoʻomaka ʻo ia e hopohopo i nā hui he nui mai kēlā mau hōʻike āpau kahi i hoʻolaha ʻia ai ka nānā ʻana uila uila e ke aupuni o ʻAmelika Hui Pū ʻIa.

I loko o ka makaʻu o kēia loaʻa ʻana, ʻO ka ʻoiaʻiʻo he nui nā loea i pili i ka nāwaliwali i hoʻonui ʻia A ke hoʻonāukiuki nei kēlā me kēia i kēia hoʻolaha. He laʻana o kēia iā mākou i nā ʻōlelo a ʻO Werner koch, mea kākau alakaʻi o GNU Privacy Guard nāna i ʻōlelo maoli he ala maoli ke ala e hōʻemi ai i kēia pilikia pau ka hoʻohana ʻana i nā leka uila HTML a hoʻohana i ka hoʻopunipuni i hōʻoia ʻia.


Hoʻopili ka ʻike o ka ʻatikala i kā mākou kumumanaʻo o ka hoʻoponopono hoʻoponopono. E hōʻike i kahi kaomi hemahema ʻaneʻi.

E lilo i mea mua e wehewehe

E waiho i kāu manaʻo

Kāu leka uila aae? E,ʻaʻole e paʻiʻia.

*

*

  1. He kuleana no ka ʻikepili: Miguel Ángel Gatón
  2. Ke kumu o ka ʻikepili: kaohi SPAM, hoʻokele ʻōlelo.
  3. Legitimation: Kou ʻae
  4. Ka kamaʻilio ʻana o ka ʻikepili: ʻaʻole e hōʻike ʻia ka ʻikepili i nā ʻaoʻao ʻekolu koe ka mana o ke kānāwai.
  5. Pūnaewele mālama: Pūnaewele i mālama ʻia e Occentus Networks (EU)
  6. Nā Kuleana: I kēlā me kēia manawa hiki iā ʻoe ke palena, hoʻōla a kāpae i kāu ʻike.

bool(ʻoiaʻiʻo)