4 ms·
So, more half-assed entropy estimation voodoo neither verified nor endorsed by actual cryptographers? For goodness' sake, Fortuna already exists. What happened
by nshepperd 10y ago
So, more half-assed entropy estimation voodoo neither verified nor endorsed by actual cryptographers?
For goodness' sake, Fortuna already exists. What happened to "don't invent your own cryptography"?
- acqq 10y agoIf I understood it, this change is supposed to be fully compatible with the existing interfaces and assumptions, it just claims to give more bits faster, using Fortuna would mean more changes at once and would mean the client code would have to change. Which is easier for OpenBSD to do than it is for Linux.
- twic 10y agoHow would it change the client code? If you use Fortuna to implement /dev/{u,}random, then the client code can just carry on opening that and reading as many bytes as it needs.
- tptacek 10y agoReplacing the LRNG with Yarrow or Fortuna or something like it would not break any client code, because no sane client code can rely on when /dev/random decides to block --- even by the LRNG's broken definition, that blocking happens at random, and could be deferred indefinitely if enough "entropy" were available.