Re: Twofish soruce code outside the U.S.

New Message Reply About this list Date view Thread view Subject view Author view

William H. Geiger III (whgiii@invweb.net)
Mon, 15 Jun 1998 04:57:02 -0500


-----BEGIN PGP SIGNED MESSAGE-----

In <Pine.HPP.3.95.980615062217.6489C-100000@b0fh.sweden.hp.com>, on
06/15/98
   at 06:27 AM, Kevin Steves <stevesk@sweden.hp.com> said:

>On Sun, 14 Jun 1998, Bruce Schneier wrote:
>> >http://www.healey.com.au/~reason/twofish/
>> >
>> >Will shortly be mirrored somewhere in the socialchange.com.au domain was
>> >well. Will keep you posted.
>> >
>> That was fast.

>Can you make PGP signatures (or at least MD5 checksums) of your Twofish
>implementations available, so we can verify mirrored copies?

A while back, last year or the year before I showed the list a technique
for PGP signing C source code so It could be compiled without
modifications:

Step one:

Add a line with "*/" at the top of the file and add a line with "/*" to
the bottom of the file.

Step two:

PGP clear-sign the file.

Step three:

Add a line with "/*" at the top of the file and add a line with "*/" to
the bottom of the file.

Now you will have a PGP Clearsigned C code file that can be verified and
compiled without any modifiections. This will also work with *.h files or
any other files that allow you to comment out a block of text. This will
not work where the compiler/interpreter requires a comment symbol at the
begining of every file ( //, #, ...ect).

This has an advantage over just archive signatures in an environment where
only some of the source code may be retained and repackaged or where the
sourced code may be modifed (ie for porting) and then repackaged. In the
case with the porting issue it allows the person to include the original
and modifed source code (or patch).

I use a simple rexx script to sign all my files, & build my archives. Perl
or a shell script could be used just as well.

- --
- ---------------------------------------------------------------
William H. Geiger III http://users.invweb.net/~whgiii
Geiger Consulting Cooking With Warp 4.0

Author of E-Secure - PGP Front End for MR/2 Ice
PGP & MR/2 the only way for secure e-mail.
OS/2 PGP 5.0 at: http://users.invweb.net/~whgiii/pgp.html
- ---------------------------------------------------------------
 
Tag-O-Matic: If you want it done right, forget Microsoft.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a-sha1
Charset: cp850
Comment: Registered_User_E-Secure_v1.1b1_ES000000

iQCVAwUBNYTyq49Co1n+aLhhAQGstwP/Wa9Lf6LdE6itAedHqRIRAMZ4r6TaFoCM
vqyfJrQ4L/QnMjCVkn3WhtOd2mv6FsCCygONMg08gVqq6716LTCutW6PLjHtD5NN
I5fSgWL/fsqTm7PL7DFgF7tM6YMADFIAo1532VZ9G8Rw6CZHN2gg9IVqOv7u787s
dIBxvPZXc20=
=6TL9
-----END PGP SIGNATURE-----


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:18:31 ADT