3 ms·
I'm not a crypto expert but I find the arguments of this article (and tptacek et al) convincing. The one thing I still don't like about /dev/urandom is this: u
by tkiley 13y ago
I'm not a crypto expert but I find the arguments of this article (and tptacek et al) convincing.
The one thing I still don't like about /dev/urandom is this: urandom's proponents say that it only fails on first boot, because modern linux distros capture entropy to seed urandom on following boots.
This means that in order for /dev/urandom to be ok, I have to depend on specific functionality of both the kernel and the linux distribution. In contrast, /dev/random is (arguably) harder for the distro to mess up, as it's primarily a function of the kernel.
Given the number of times distros have screwed up crypto, what are the odds that this will someday matter in the real world?