4 ms·
Probably more lacking automated test coverage than bad luck? For security critical RNG code, seems to me you’d really want to have a test where it generates a t
by yashap 2y ago
Probably more lacking automated test coverage than bad luck? For security critical RNG code, seems to me you’d really want to have a test where it generates a tonne of random numbers and asserts that they’re all unique.
- tizvoivo 2y ago[dead]
- bdonlan 2y agoIn this case, the problem was the seed was low entropy, so if you generated a bunch of random numbers with a single initialization of the RNG seed you would get unique values. It's a tricky scenario to test for if you don't know of the failure mode...
- gunapologist99 2y agoIt's not possible to assert that a number is not random (or is). You can look at it and you just don't know. This was the issue with the PRNG blackbox mixing. Obligatory Dilbert https://imgur.com/uR4WuQ0 https://imgur.com/uR4WuQ0 and XKCD: https://xkcd.com/221/ https://xkcd.com/221/
- brokenmachine 2y agoSo if you rolled a dice a few times and happened to get the same number, you'd throw the dice away for not working properly?
- account42 2y agoNo but you might investigate how even the dice really is and if it only happens with dice that have the shiny red swirl painted on one side then maybe consider not doing that.