5 ms·
Ask HN: What's the most secure cross-platform RNG option?
I'm writing a very encryption heavy piece of software, and security is very important. With the big focus on RNG lately, I've really wanted to know what is the most secure. Hardware is ruled out due to possible backdooring.
- rosenjon 13y agoYou could try this out. http://www.random.org/clients/http/ http://www.random.org/clients/http/ Of course, there is a trust issue with this service potentially. However, supposedly, they use a random noise technique that is "true random".
- nulldata 13y agoI can't expect the user to have an internet connection when needed. And having to send something vital as this over an HTTP is just not an option.
- tptacek 13y agoIf those are the only two reasons you wouldn't get crypto randomness directly from "random.org", you shouldn't be designing cryptosystems to begin with.
- throwaway812 13y agoJust read from `/dev/urandom` (free Unices). It doesn't require any 3rd party libraries, always exists, and has a great track record compared to e.g. OpenSSL. <editorializing>On Windows (or proprietary Unix), you can't verify the implementation of any option for randomness.</editorializing>
- andrewcooke 13y agoyou ask for cross-platform and you don't define "most secure". so it seems like the "right" answer is the one that is believed to be secure and is as cross-platform as possible. and i think that would be openssl. it's famous for causing bugs/weaknesses from being used incorrectly, but afaik it's secure if used correctly. and it compiles on a wide range of hardware.
- tptacek 13y agoJust use /dev/urandom.