[Webfunds-users] AsciiArmoured challenge
Ian Grigg
iang@systemics.com
Tue Mar 28 22:41:42 2000
Edwin,
> Allright then, here it is. I didn't knew these things could expire.
Next release, they will expire after 5 days, not 1.
> Would the error message for an expired message resemble the message
> I got?
Nope.
> -----BEGIN SOX MESSAGE-----
> Version: 2.0.0
> Comment: SOX by Systemics
>
> AAENUDk0OTQ0MDczMDcyMBSbr+/hIKmPgr6kG2e+NsNy72Si8wAUnHyee7VkIkl3rqhnRijdAe4
> 9u4AAAAAAAAD6AAAAAAAAAAGmD0AAADdFEDPiYEXMIGUMA0GCSqGSIb3DQEBBAUAA4GCAACmGXs
> 01/hvIEJfDBSIwah2QZ5b6yNPnv8jFMWJ/kCUPHNUZqCFqypEVspmOT2It62ySKhhA5U6uGdqtA
> 3bkb5wnthWHG5H8qRwTKTvNBLaqU+LYTAbPVjuriWGKjV2jIp2sFN8nt4gQILGfTKXnqC7MkRkq
> M+ron91zH+1GyA==
> =8PEw
> -----END SOX MESSAGE-----
Well, you probably can't tell from where you're standing but
this payment is no good just by inspection: It is missing a
character of each of the lines. Not just any character, but
a char in the middle which is truley wierd. For example, here's
a good payment (also expired), with each line followed by the
line of the bad payment above:
-----BEGIN SOX MESSAGE-----
Version: 2.0.0
Comment: SOX by Systemics
AAENUDk1NDAxOTIzMjcxOBR3XpAb/Crzic7dUSD2Al6r+OCngQAUnHyee7VkIkl3rqhnRiOjdAe4
AAENUDk0OTQ0MDczMDcyMBSbr+/hIKmPgr6kG2e+NsNy72Si8wAUnHyee7VkIkl3rqhnRi jdAe4
9u4AAAAAAAAAAAAA///////+18IAAADeJR9w0IEWMIGTMA0GCSqGSIb3DQEBBAUAA4GBAB0BD2Ek
9u4AAAAAAAAD6AAAAAAAAAAGmD0AAADdFEDPiYEXMIGUMA0GCSqGSIb3DQEBBAUAA4GCAA CmGXs
xL1KJYFOv5UIM5B1BxKjKX886GALOuLx8UWqpsmojiVIbDhX3Ddwsy0FZOeV9kybnJKXFGbVgUd4
01/hvIEJfDBSIwah2QZ5b6yNPnv8jFMWJ/kCUPHNUZqCFqypEVspmOT2It62ySKhhA5U6uGdqtA
TUzfCKN0JqF1Une87uTexM56yVttJOfAZX7rsR5CW0aH0zRRQVMy8Ci75Fr9AvILVM9AJsz0PCoJ
3bkb5wnthWHG5H8qRwTKTvNBLaqU+LYTAbPVjuriWGKjV2jIp2sFN8nt4gQILGfTKXnqC7MkRkq
jSz7QVCdSjcO
M+ron91zH+1GyA==
=g/7N
=8PEw
-----END SOX MESSAGE-----
I notice one things other than the missing char - in the first two lines,
one can see that it is a zero in the same position that has been stripped.
I'd say that something like Mime stripped out the char. Or C&P. After
70 chars.
We do know that there are horrific things that can happen to text payments
like the above even when ascii armoured. I think the real solution is that
we need a new AA format that is more robust than PGP's. E.g., shorter lines
is a good start.
Fancy giving it a go? After PGP Sigs of course!
iang