Alternate egd socket

Matthias Urlichs smurf at noris.net
Thu Feb 10 18:11:19 CET 2000


Hi,

Werner Koch:
> IMHO, if someone is able to access the random seed file, he will also
> be able to access the secret keyring ... well, and then he loads it
> down starts a dictionary attack and in kost cases he will be able to
> get the passphrase.

Bah, dictionary attack... if you're root anyway, wait until the user
starts up GnuPG, and trace its read() calls. Bingo.

-- 
Matthias Urlichs  |  noris network GmbH   |   smurf at noris.de  |  ICQ: 20193661
The quote was selected randomly. Really.    |      http://www.noris.de/~smurf/
-- 
There is something that is much more scarce, something finer far,
something rarer than ability.  It is the ability to recognize ability.
                                -- Elbert Hubbard



More information about the Gnupg-devel mailing list