Hacker News new | ask | show | jobs
by pvg 2302 days ago
You can straight up google 'pgp' and 'downgrade attack' so maybe that's not that great an example.
1 comments

Do you have an actual example? Normally when people talk about a downgrade attack on OpenPGP they just assume it is somehow possible without actually checking that it is.

Note that I am only claiming that downgrade attacks are technically impossible for OpenPGP due to the way that it works. To break the protection against downgrades means that you have to break the root cryptography. That might not be true for other stuff... Makes for a great example though...