Point of view regarding LISA 2002

Werner Koch wk@gnupg.org
Wed Oct 2 09:15:02 2002

On Tue, 1 Oct 2002 14:00:51 -0500, Shawn K Quinn said:

> Sounds pretty devious, but this will probably take up a noticable amount 
> of CPU and (in the case of boxes with a proper /dev/random) the effect 
> on the entropy pool might well be noticed.

You don't need good random for bogus keys.

> I know KMail at least does not let you encrypt attachments easily; they 
> have to be encrypted by hand and attached that way. The potential for 
> this kind of worm may well be part of the reason for this.

No the reason is that KMail had no real MIME framework; the way
attachment used to be handle was a hack.  KDE 3.1 comes with a better
working MIME implementation.