Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: GnuPG: users

Re: Oracle behavior in Gnupg? //

 

 

GnuPG users RSS feed   Index | Next | Previous | View Threaded


wk at gnupg

Jul 31, 2012, 2:24 AM

Post #1 of 1 (138 views)
Permalink
Re: Oracle behavior in Gnupg? //

On Mon, 30 Jul 2012 16:59, harningt [at] gmail said:

> it? If so, then I'd suggest that a "quiet" execution be performed that
> way only the exit code can be used that it's failure.

You should not rely on the exit code but parse all the information
returned by GPG. GPGME makes this easy.

Given that GPG is just a tool and not a complete automated cryptographic
system, the developer needs to care about certain attacks by himself.
There are several points to watch out for, not only oracle attacks, but
for example also replay attacks.


Salam-Shalom,

Werner

--
Die Gedanken sind frei. Ausnahmen regelt ein Bundesgesetz.


_______________________________________________
Gnupg-users mailing list
Gnupg-users [at] gnupg
http://lists.gnupg.org/mailman/listinfo/gnupg-users

GnuPG users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.