Re: Change OpenPGP Smartcard PIN retry counter

Chandler Davis via Gnupg-users <[email protected]>
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <g5le2EPOKQE7-VoIqKviehNc9HEguveSAGJleNkSUkFpI_BoAz4UluKsacPuUmE-RVc3sKCmmqCx8yUqDvdUZVZXMTL20L6d1heF2F05bBQ=@chandlerdavis.cc>
On Wednesday, November 19th, 2025 at 3:07 PM, Borden via Gnupg-users <[email protected]> wrote:

> Pardon my ignorance, but I thought GPG card hardware sets the PIN counter to lock or destroy the private key after failed attempts precisely to stop someone from trying to brute force the PIN?

Yes, that's correct. If the retry counter is maxed out, it will be locked and you'll have to use the unblocking pin (PWD.2 I think) to reset the counter and make it usable again.

If you don't know the unblocking pin, the only choice is to reset the card and put new keys on it. You *may* be able to do something with the admin PIN as well, but I don't remember off the top of my head.

> Am I to understand that we cannot rely on a PIN counter?

What we're discussing here is how to increase the number of PIN retries that are allowed before that locking happens. The counter still protects from brute forcing.

The default is 3 attempts, but I think 5 is still reasonable and a bit "safer" in terms of not accidentally locking yourself out.

--
Best,
Chandler Davis

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users
publickey - [email protected] - 0x806B3070.asc (application/pgp-keys, 1.2 KB)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEaQ6uERYJKwYBBAHaRw8BAQdAIPKKOe+zE0diRrVyJngquM1MotVQJyoT
GuMQljs93p/NJENoYW5kbGVyIERhdmlzIDxtZUBjaGFuZGxlcmRhdmlzLmNj
PsKOBBMWCgA2FiEEgGswcAPCWnIj+us0APg8u/VuvoEFAmkOrhECGwEECwkI
BwQVCgkIBRYCAwEAAh4BAheAAAoJEAD4PLv1br6BnzIBAPcakqsiqNknXheC
Rrr5g68n++n0UUjYiI8cs4gS9ZWtAPwOfpglhn37IkHzm1O09eEOX9Ep6ZJa
+TnPMiPcPihnC84zBGkOrk0WCSsGAQQB2kcPAQEHQPtD4iX44psDccW0w/Yx
mt/wdeJcHhpOEczYNgPUMUnmwsAvBBgWCgAgFiEEgGswcAPCWnIj+us0APg8
u/VuvoEFAmkOrk0CGwIAgQkQAPg8u/VuvoF2IAQZFgoAHRYhBL7QThr5oYT4
suuONWLnSS+A9vSXBQJpDq5NAAoJEGLnSS+A9vSXiRkBAIIqFGMKpOcW6IeN
CkJSY3+vu9Yhy7vY24hj+ncHzrQ3AQCNn2eoTb1lXqNoIXq46Q0O4y5T5e0B
I1iEk1HxBVzrD6w4AP4mG4I+7m6luPqWyjX1F8mCsmfpMVDfbMu2a3xAjfGK
gAEA4T5j8I/kb8gBQMaAjq2xeTbfEk01iFk3VW+Is+ZS/wjOOARpDq5lEgor
BgEEAZdVAQUBAQdAdUnZxWCe4YIrMRWlljl+9McRTxxQC9/L8tUqAu54tlUD
AQgHwngEGBYKACAWIQSAazBwA8JaciP66zQA+Dy79W6+gQUCaQ6uZQIbDAAK
CRAA+Dy79W6+gccDAQD4pG8+6ymbBZEavRGjon4eihk54JlJB9KpswSvuJXD
ZAEAnKgowQmJ/vA4gTSlUEiWi3jQrlIlzmQZgfZ9kxmwkgPOMwRpDq59Fgkr
BgEEAdpHDwEBB0CyMQwXa77CNIY+PiU0Mn+0UF9FVudW+KyBLq/2A2nkg8J4
BBgWCgAgFiEEgGswcAPCWnIj+us0APg8u/VuvoEFAmkOrn0CGyAACgkQAPg8
u/VuvoE8VQD+NWZFVZ8MQ5tyVeUkTwZjKAhN7y/Y3QffL4CdFSD0Sc8A/1Rx
oqmjJmrbTECrVGzzUR9fkwTsHxglzw4oaadmo8wF
=TvwI
-----END PGP PUBLIC KEY BLOCK-----
signature.asc (application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0FgmkeKqMJEGLnSS+A9vSXRRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmcOrbIygIqm++CvBY/ooM4iTSy6W4NjwToe6FPm
WXi9LhYhBL7QThr5oYT4suuONWLnSS+A9vSXAAB+MQEA9vVlqvVaRvVa+DgG
U77n9ctiqvoMUbMHm+srg58tqO0BANt3ZFlJtt+qIftGkNVK2caU1zWxeVgN
oOkU6nPH8nwN
=p1W9
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.