Robert J. Hansen rjh at
Sun Jan 30 04:35:44 CET 2022

> Ok, you made me actually look at pgp263iamulti06. :-)

I almost feel like I should apologize.

> However, the entropy gathering seems overly optimistic:


That's quite a bit worse than I remember.  (I haven't looked at 2.6.3 
source code in probably 25 years.)

So, yeah.  I'm comfortable calling the 2.6.3 CSPRNG system fatally 
compromised due to inadequate entropy gathering.

Thank you for looking into this!
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 236 bytes
Desc: OpenPGP digital signature
URL: <>

More information about the Gnupg-users mailing list