| |
| | CERT Advisory CA-2000-09 Flaw in PGP 5.0 Key Generation |
 | | Under certain circumstances, PGP v5.0 generates keys that are not sufficiently random, which may allow an attacker to predict keys and, hence, recover information encrypted with that key. |
 | | Keys produced non-interactively with PGP v5.0 on a system with a /dev/random device may be predictable, especially those produced in an environment without a pre-existing randseed.bin file. |
 | | Documents encrypted with a predictable key may need to be re-encrypted with a non-vulnerable key, if your particular circumstances warrant it; that is, if the information still needs to be encrypted. |
| www.cert.org /advisories/CA-2000-09.html (1072 words) |
|