Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And to make it even more clear: the notion that /dev/urandom first does "the right thing" and then (after entropy has been exhausted) falls back on the "worthless thing" (the CSPRNG) is absolutely and categorically wrong.

Both /dev/urandom and /dev/random always do "the worthless thing".

What people consider "the right thing", namely handing out raw collected random bits without any postprocessing, would even be catastrophic.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: