Return-Path: Delivered-To: apmail-jakarta-tomcat-user-archive@apache.org Received: (qmail 88993 invoked from network); 7 Jun 2002 10:34:14 -0000 Received: from unknown (HELO nagoya.betaversion.org) (192.18.49.131) by daedalus.apache.org with SMTP; 7 Jun 2002 10:34:14 -0000 Received: (qmail 14354 invoked by uid 97); 7 Jun 2002 10:33:56 -0000 Delivered-To: qmlist-jakarta-archive-tomcat-user@jakarta.apache.org Received: (qmail 14302 invoked by uid 97); 7 Jun 2002 10:33:55 -0000 Mailing-List: contact tomcat-user-help@jakarta.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Subscribe: List-Help: List-Post: List-Id: "Tomcat Users List" Reply-To: "Tomcat Users List" Delivered-To: mailing list tomcat-user@jakarta.apache.org Received: (qmail 14282 invoked by uid 98); 7 Jun 2002 10:33:55 -0000 X-Antivirus: nagoya (v4198 created Apr 24 2002) From: "Power-Netz \(Schwarz\)" To: "Tomcat Users List" Subject: AW: Security problem? Date: Fri, 7 Jun 2002 12:33:08 +0200 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0) In-Reply-To: <11EF704D97C1D41186520002B30902C94658E3@mucs001.ect-telecoms.de> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 Importance: Normal X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N > > In response to M. Schwarz, with public key encryption schemes > know the clear > text of really doesn't help very much at cracking the private key. Besides > which, the user (presumably) knows what the price of the thing > they are buy > anyway right? So they know what the cleartext of the message is > whether it's > sent with the message or not. > Although this does bring to my mind a real weakness in my suggestion. Once no, they know only the price, not the form of the data, which of course can be different in the encrypted data as in the clear text, which was my weakness :) M.Schwarz -- To unsubscribe, e-mail: For additional commands, e-mail: