Speed and security of /dev/urandom

Ben Laurie benl at freebsd.org
Fri Jul 18 21:57:40 UTC 2014


On 18 July 2014 00:41, Steven Chamberlain <steven at pyro.eu.org> wrote:
> So I wonder, could a simplified arc4random for FreeBSD use Yarrow
> directly, to avoid making any of these sorts of mistakes we've seen?

Discovering that its OK to use this mechanism seems as vulnerable to
mistakes as the mistakes we've seen. I don't have good suggestions on
how to fix this.


More information about the freebsd-security mailing list