5 ms·
> As always, my advice for things like this is that if you’re in need of true random numbers in your shell script then you should probably stop writing whatever
by ary 4y ago
> As always, my advice for things like this is that if you’re in need of true random numbers in your shell script then you should probably stop writing whatever it is you are writing as a shell script.
The use of "true" here seems ambiguous.
Does this statement mean that you discourage creation of cryptographic applications with shell scripts, you discourage use of shell scripts to orchestrate applications that use /dev/urandom for any reason, or something else entirely?
(first, and only edit: This comment is in good faith, so if you're downvoting please respond to let me know why)
- noam_k 4y ago"True random" as opposed to "pseudo random", which is not cryptographically secure.
- jimktrains2 4y agoThere are cryptographically secure pseudorandom generators. In fact all sources non-hardware (i.e. /dev/random and /dev/urandom) are psuedo random as are the keystream generators for most algos that use one.
- noam_k 4y agoTIL. Thanks!
- ary 4y agoYes, I'm aware of that. The commenter seems to be implying that one should stop using a shell script when one needs "true" random, and I'm curious as to why since one can call out to Perl, Python, etc. The linked gist doesn't appear to be making the case for using its recommendations in cryptographic applications so what I'm ultimately after is what the commenter thinks is being done in the shell that's inappropriate.
- MattPalmer1086 4y agoIncorrect. I'm not sure what you mean by "true random", and we could get into some interesting philosophical discussion on that. However, all software random number generators are pseudo random, including cryptographic ones. They are called CSPRNGs, which stands for Cryptographically Secure Pseudo Random Number Generator.