Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Nods

You're very unlikely to be continually reseeding your own DBRG with new entropy, so it will be less secure than /dev/urandom, which is.

Suspiciously bad advice, there, from what I can see.



Just as a random counter-example, Openssl does use that method. But it actually seeds from urandom, rather than random... And fails when forking/threading by default. :(

But yes, that's not common. (more info: http://wiki.openssl.org/index.php/Random_Numbers)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: