Alternate egd socket

Matthias Urlichs smurf at
Thu Feb 10 18:11:19 CET 2000


Werner Koch:
> IMHO, if someone is able to access the random seed file, he will also
> be able to access the secret keyring ... well, and then he loads it
> down starts a dictionary attack and in kost cases he will be able to
> get the passphrase.

Bah, dictionary attack... if you're root anyway, wait until the user
starts up GnuPG, and trace its read() calls. Bingo.

Matthias Urlichs  |  noris network GmbH   |   smurf at  |  ICQ: 20193661
The quote was selected randomly. Really.    |
There is something that is much more scarce, something finer far,
something rarer than ability.  It is the ability to recognize ability.
                                -- Elbert Hubbard

More information about the Gnupg-devel mailing list