3 ms·
This is the most likely scenario. While I don't know Java technically, .NET has a similar "vulnerability" if you use more than one RNG. It uses time to seed new
by w0rd-driven 13y ago
This is the most likely scenario. While I don't know Java technically, .NET has a similar "vulnerability" if you use more than one RNG. It uses time to seed new values and the general rule is you use this as a singleton/static app-wide. If you don't do this, all your rng's share the exact same value.
It's really awkward to stumble into as all the evidence points to the framework but when you rtfm you realize no, its really pebkac.
I'm not saying this can't be a vulnerability in the framework, just this is the most likely scenario.
- Dylan16807 13y agoA secure random number generator wouldn't seed based on time in the first place, though.
- brazzy 13y agoEven Java's non-secure RNG doesn't do that (anymore): public Random() { this(++seedUniquifier + System.nanoTime()); }