3 ms·
As I am uninformed on the subject, could you tell me the difference between /dev/random and /dev/urandom?
by andruby 9y ago
As I am uninformed on the subject, could you tell me the difference between /dev/random and /dev/urandom?
- filleokus 9y agoQuite a long read, but I think it explains the situation quite well: https://www.2uo.de/myths-about-urandom/ https://www.2uo.de/myths-about-urandom/
- snakeanus 9y agoAlso an interesting and related article https://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers/ https://sockpuppet.org/blog/2014/02/25/safely-generate-rando...
- Tomte 9y agoUnfortunately, the article isn't in the best shape right now. Back when it was written, things were clear: random and urandom are the same. Then came getrandom as a distraction. Now urandom is based on chacha. So it's different (but not worse – still, harder to explain). The article's structure couldn't easily accomodate those changes, and time was and is in short supply, and so it's not wrong, but much less forceful and clear than it used to be. I hope it shapes up soon, but don't promise anything! Still, I don't know a more up-to-date article. Maybe Thomas Pornin has something newer on StackOverflow?
- Tomte 9y agoYou're right, that was too short and thus too harsh. Please accept my apologies. So a short roundup: /dev/random and /dev/urandom used to be exactly the same (on Linux), except that /dev/random did some voodoo "entropy estimation" that the Linux kernel guys are totally in love with, but everyone else doesn't trust anyway. Even if there was a plausible model how to estimate entropy, which there isn't. In the meantime things have changed quite a bit. But the main thing to know is the same: /dev/urandom is the device you want to use for cryptographic randomness. /dev/random is an oddity that will be there forever because Linux takes backwards compatibility (for user space) extremely seriously. (On other Unixoid platforms you also want /dev/urandom) If you can use syscalls and don't need a device, use getrandom(2) over /dev/urandom. It's better. Oh, and please note that the Linux man pages have been updated! They now state clearly that /dev/urandom is suitable for cryptographic use. Of course, lots of old man pages floating around on the web.