4 ms·
I am curious. How do you know if this is secure or not? Is there any publication or article available for this slightly time-saving but potentially dangerous ch
by nemonemo 8y ago
I am curious. How do you know if this is secure or not? Is there any publication or article available for this slightly time-saving but potentially dangerous choice?
- segfaultbuserr 8y ago1. The official man page. The /dev/random interface is considered a legacy interface, and /dev/urandom is preferred and sufficient in all use cases, with the exception of applications which require randomness during early boot time; for these applications, getrandom(2) must be used instead, because it will block until the entropy pool is initialized. 2. https://www.2uo.de/myths-about-urandom/ https://www.2uo.de/myths-about-urandom/
- tomjakubowski 8y agoNot that I disagree with you, but which are the official man pages for /dev/urandom? It's my recollection that the advice therein varies from OS to OS.
- segfaultbuserr 8y agoThis page is part of release 4.16 of the Linux man-pages project. A description of the project, information about reporting bugs, and the latest version of this page, can be found at https://www.kernel.org/doc/man-pages/ https://www.kernel.org/doc/man-pages/. And only Linux has /dev/urandom.
- deleted 8y ago[deleted]
- floatboth 8y agoBSDs (incl. macOS) have /dev/urandom, but it's the same thing as /dev/random. Both don't ever block after they've been filled initially at boot time.
- loeg 8y agohttps://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers/ https://sockpuppet.org/blog/2014/02/25/safely-generate-rando... (Note, that's from 2014; today I would recommend getrandom() instead.)
- masklinn 8y ago> this slightly time-saving but potentially dangerous choice? The one and only danger is during the machine's boot process, because while /dev/random and /dev/urandom use the same data: * on linux /dev/random has a silly and unfounded entropy estimator and will block at arbitrary points (used to be a fad at some point, but cryptographers have sworn off it e.g. Yarrow had an entropy estimator but Fortuna dropped it) * also on linux, /dev/urandom never blocks at all, which includes a cold start, which can be problematic as that's the one point where the device might not be seeded and return extremely poor data In fact the second point is the sole difference between getrandom(2) and /dev/urandom. If you're in a steady state scenario (not at the machine boot where the cold start entropy problem exists) "just use urandom" is the recommendation of pretty much everyone: tptacek, djb, etc… https://www.2uo.de/myths-about-urandom/ https://www.2uo.de/myths-about-urandom/ https://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers/ https://sockpuppet.org/blog/2014/02/25/safely-generate-rando... http://blog.cr.yp.to/20140205-entropy.html http://blog.cr.yp.to/20140205-entropy.html (see bottom of page)
- cesarb 8y ago> In fact the second point is the sole difference between getrandom(2) and /dev/urandom. AFAIK, there's another important difference: getrandom(2) doesn't use a file descriptor (so it'll work even if you're out of file descriptors, or in other situations where having an open fd is inconvenient), and it doesn't need access to a /dev directory with the urandom device.