4 ms·
> Some SecureRandom Thoughts I feel like the author of the post isn't giving this the severity that it deserves. The title makes it sound like a thought experi
by dekz 13y ago
> Some SecureRandom Thoughts
I feel like the author of the post isn't giving this the severity that it deserves. The title makes it sound like a thought experiment, here is an example where the original title is (let's face it) shit and the editorial title here is relevant.
- healsjnr1 13y agoAgreed. The whole thing is a bit blase. Also, anyone else find it concerning that they advocate presenting /dev/urandom as SHA1-PRNG when it isn't? I don't even see why they did this? They could have wrapped the default SecureRandom and forced it to seed bytes with /dev/urandom. Also, why are they writing to /dev/urandom??
- tptacek 13y agoPresumably because some Android devices don't boot cold with a lot of entropy, so there's a virtue in helping kickstart it.
- taspeotis 13y agoI'm a layperson when it comes to cryptography. Can you clarify how much entropy a device would need to become cryptographically secure, and the profile of an Android device that couldn't collect enough entropy quickly? E.g. most devices could collect battery %, 3G radio noise levels, wifi noise, readings from the capacitive touch sensors, accelerometer, microphone etc., yes?
- logn 13y ago1.21 gigawatts!
- marshray 13y ago> Can you clarify how much entropy a device would need to become cryptographically secure 200 bits.
- healsjnr1 13y agoThere is no magic number needed to make a device "cryptographically secure". It depends entirely on the operations being performed. In general if you generating Keys, the DRBG or PRNG used in key generation needs to be seeded with entropy equal to the security strength of the key. For example: If you are generating 128 bit AES keys, the DRBG needs to be seeded with at least 128 bits of entropy. If you generating 2048 bit RSA keys you'll need 112 bits of entropy.