1. Operator correctly runs: cat /dev/urandom > seed.bin
2. Filesystem corruption fills seed with nulls/spaces (happens in production)
3. Sunlight silently generates predictable keys from corrupted seed
4. CT log operates "normally" - valid signatures, no errors
5. Anyone knowing about corruption can recreate the private keys
What other "end-user" crypto-related app runs with a user-produced seed to generate key pairs on the fly?