The FreeBSD /dev/random was originally based on the Yarrow paper that is 
given as a reference in the paper above.  But I think the current 
implementation is more similar to to the version of Yarrow that is 
discussed in Bruce Schneier's "Practical Cryptography".  I'm not sure if 
that is a coincidence or not.

The paper mentioned above only briefly mentions Yarrow, and doesn't 
mention the FreeBSD implementation, so it's hard to compare the two.

At first glance, both systems appear strong.

