LedgerHQ / app-openpgp

OpenPGP Card Application
Apache License 2.0
123 stars 21 forks source link

Disable 'GET DATA' on private key DOs #28

Closed jpathy closed 6 years ago

jpathy commented 6 years ago

Hello, as i see here: https://github.com/LedgerHQ/blue-app-openpgp-card/blob/c07cb00cb61035fe13af668c3caf11f2ea0af044/src/gpg_data.c#L43-L55 the private key DOs are readable, i believe this shouldn't be possible for pgpcards, the seeded mode should be used, if this property is desired.

cslashm commented 6 years ago

that's not private key. Just private user data, not used by gnupg