2 ms·
To be completely correct: On modern kernels, /dev/urandom is not an interface to the kernel entropy pool. It is rather a ChaCha20 Cryptographic Random Number
by tytso 7y ago
To be completely correct: On modern kernels, /dev/urandom is not an interface to the kernel entropy pool. It is rather a ChaCha20 Cryptographic Random Number Generator which is periodically seeded from the kernel entropy pool.
getrandom(2) uses the same ChaCha20-based CRNG. The main advantage is that it doesn't require that you be able to open a file descriptor. (There were some obscure attacks on some userspace where the attacker would exhaust the number of file descriptors, and the sloppy userspace code wasn't checking error returns, and so it wasn't actually reading from /dev/urandom. Getrandom(2) is supposed to be foolproof --- which is hard, given how ingenious fools can be, but at least it's harder to screw up using getrandom(2). It also works in the completely empty chroot scenario referenced in the grandparent of this post.