Re: Unsafe configuration of the pinentry program
Werner Koch via Gnupg-users <[email protected]>
| Newsgroups | gmane.comp.encryption.gpg.user |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 30 Dec 2025 14:55, Marius Spix said: > directory can easily compromise gpg-agent by overriding the key > pinentry-program in ~/.gnupg/gpg-agent.conf This is anyway TILT - GAME OVER. There are hundereds of ways to compromise a system if you have write access to the configuration files. Thanks for asking. Shalom-Salam, Werner -- The pioneers of a warless world are the youth that refuse military service. - A. Einstein _______________________________________________ Gnupg-users mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-users
openpgp-digital-signature.asc
(application/pgp-signature, 284 B)
-----BEGIN PGP SIGNATURE----- iJ8EARYKAEcWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCaVPmgRsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMSwyLDINHHdrQGdudXBnLm9yZwAKCRAZzByeCFsQevbVAQDf 1NfvxY1rjH1QhWUNRz4WTs9HJcKQ3cLSJInYM/rHygEAlyurnjb09xHPZAXCLMdc vDYyI9GniP6NmwvRjHAJzg0= =rPuA -----END PGP SIGNATURE-----