Re: FreeBSD rnd bug

Patrick Welche <[email protected]>
Newsgroups gmane.os.netbsd.devel.security
Message-ID <20150220155250.GB1875@quantz>
On Fri, Feb 20, 2015 at 09:41:48AM -0600, J. Lewis Muir wrote:
> On 2/20/15 7:55 AM, Taylor R Campbell wrote:
> > Yes, for cprng_strong.  However, statistical tests on the output of
> > a cryptographic PRNG will not detect failure to seed it.  They will
> > detect only catastrophic bugs in the PRNG itself.  (They will also
> > sometimes spuriously fire, as is the nature of statistical tests on
> > uniform random data.)
> 
> See Dilbert's tour of accounting:
> 
>   http://dilbert.com/strip/2001-10-25
> 
> :-)

Thanks for sorting that out - for other reasons, I read rnd(4) yesterday,
and wondered:

         o   An utterance from an accounting troll who always says `nine' has
             zero bits of entropy.

"What troll?!"

P
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.