4 ms·
That's a bad idea. You shouldn't be trusting random.org with your random data (what if they get hacked or something). Also if it's send over http then an attack
by Ellipsis753 13y ago
That's a bad idea. You shouldn't be trusting random.org with your random data (what if they get hacked or something).
Also if it's send over http then an attacker could listen in to the random data you were being sent (either at your end or at random.org).
Ultimately I think you'd do best to use several software methods and 2 hardware methods and just xor them all together into a single secure source of random numbers.
I mean, if you're doing this as a business the small cost of this is well worth not having to deal with your random source having issues.
- wtallis 13y ago> "...use several software methods and 2 hardware methods and just xor them all together..." An xor is only okay if you ensure that all of your RNGs are completely independent - unable to affect or observe each other, and do not draw any of their input from any shared or correlated sources. If you've got two machines seeding their entropy pools with packet timings from the same network, then XORing their PRNG output is as likely to decrease entropy as increase it.
- Ellipsis753 13y agoI do however think that I am correct in thinking that provided that any one of your sources is "true" and independent then the xor'd string of binary will be completely random. You cannot xor an unkown random binary string and make it less random.