What's the problem?
Posted Feb 19, 2003 8:28 UTC (Wed) by
Peter (guest, #1127)
In reply to:
What's the problem? by Ross
Parent article:
Mandrake security update to util-linux
Well, on a scale of people who know anything about cryptographic PRNGs, I rate quite low. (:
I had read differently on the lkml a few years back. It was stated (IIRC) that /dev/urandom was safe on systems which had
very little (or no) entropy gathered, so long as:
1) the initial entropy pool contents were unknown to the attacker
2) SHA-1 could not be reversed
I don't see any flaws in the reasoning, but then again I'm not a cryptographer :)
Ditto, squared. It sounds good anyway.
(
Log in to post comments)