next up previous
Nächste Seite: PGP2 and GnuPG Aufwärts: Basics Vorherige Seite: Hashes

Man in the middle

The weakest point in the communication based on asymmetric encryption is the knowledge about the real owners of keys. Somebody evil could generate a key pair, give the public key away and tell everybody, that it belongs to somebody else. Now, everyone believing it will use this key for encryption, resulting in the evil man being able to read the messages. If he encrypts the messages again with the public key of the real recipient, he will not be recognized easily.

This sort of attack is called ``man-in-the-middle'' attack and can only be prevented by making sure, public keys really belong to the one being designated as owner.



Kurt Garloff
2000-08-28