[Webfunds-users] AsciiArmoured challenge

Ian Grigg iang@systemics.com
Tue Mar 28 22:41:42 2000


Edwin,

> Allright then, here it is. I didn't knew these things could expire.

Next release, they will expire after 5 days, not 1.

> Would the error message for an expired message resemble the message
> I got?

Nope.

> -----BEGIN SOX MESSAGE-----
> Version: 2.0.0
> Comment: SOX by Systemics
> 
> AAENUDk0OTQ0MDczMDcyMBSbr+/hIKmPgr6kG2e+NsNy72Si8wAUnHyee7VkIkl3rqhnRijdAe4
> 9u4AAAAAAAAD6AAAAAAAAAAGmD0AAADdFEDPiYEXMIGUMA0GCSqGSIb3DQEBBAUAA4GCAACmGXs
> 01/hvIEJfDBSIwah2QZ5b6yNPnv8jFMWJ/kCUPHNUZqCFqypEVspmOT2It62ySKhhA5U6uGdqtA
> 3bkb5wnthWHG5H8qRwTKTvNBLaqU+LYTAbPVjuriWGKjV2jIp2sFN8nt4gQILGfTKXnqC7MkRkq
> M+ron91zH+1GyA==
> =8PEw
> -----END SOX MESSAGE-----

Well, you probably can't tell from where you're standing but
this payment is no good just by inspection:  It is missing a
character of each of the lines.  Not just any character, but
a char in the middle which is truley wierd.  For example, here's
a good payment (also expired), with each line followed by the
line of the bad payment above:

-----BEGIN SOX MESSAGE-----
Version: 2.0.0
Comment: SOX by Systemics

AAENUDk1NDAxOTIzMjcxOBR3XpAb/Crzic7dUSD2Al6r+OCngQAUnHyee7VkIkl3rqhnRiOjdAe4
AAENUDk0OTQ0MDczMDcyMBSbr+/hIKmPgr6kG2e+NsNy72Si8wAUnHyee7VkIkl3rqhnRi jdAe4

9u4AAAAAAAAAAAAA///////+18IAAADeJR9w0IEWMIGTMA0GCSqGSIb3DQEBBAUAA4GBAB0BD2Ek
9u4AAAAAAAAD6AAAAAAAAAAGmD0AAADdFEDPiYEXMIGUMA0GCSqGSIb3DQEBBAUAA4GCAA CmGXs

xL1KJYFOv5UIM5B1BxKjKX886GALOuLx8UWqpsmojiVIbDhX3Ddwsy0FZOeV9kybnJKXFGbVgUd4
01/hvIEJfDBSIwah2QZ5b6yNPnv8jFMWJ/kCUPHNUZqCFqypEVspmOT2It62ySKhhA5U6uGdqtA

TUzfCKN0JqF1Une87uTexM56yVttJOfAZX7rsR5CW0aH0zRRQVMy8Ci75Fr9AvILVM9AJsz0PCoJ
3bkb5wnthWHG5H8qRwTKTvNBLaqU+LYTAbPVjuriWGKjV2jIp2sFN8nt4gQILGfTKXnqC7MkRkq


jSz7QVCdSjcO
M+ron91zH+1GyA==

=g/7N
=8PEw

-----END SOX MESSAGE-----

I notice one things other than the missing char - in the first two lines,
one can see that it is a zero in the same position that has been stripped.

I'd say that something like Mime stripped out the char.  Or C&P.  After
70 chars.

We do know that there are horrific things that can happen to text payments
like the above even when ascii armoured.  I think the real solution is that
we need a new AA format that is more robust than PGP's.  E.g., shorter lines
is a good start.

Fancy giving it a go?  After PGP Sigs of course!

iang