gnutls-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Bug#448775: Uses too much entropy (Debian Bug #343085)


From: Werner Koch
Subject: Re: Bug#448775: Uses too much entropy (Debian Bug #343085)
Date: Fri, 04 Jan 2008 14:45:00 +0100
User-agent: Gnus/5.110007 (No Gnus v0.7)

On Fri,  4 Jan 2008 13:41, address@hidden said:

> We could consider doing something like that in gnutls too, to help
> applications avoid having to do it themselves.  However, the
> documentation on UPDATE_SEED seems somewhat discouraging.  I'm not sure

Let's say this description is very conservative and mostly written for
security evaluations.  The "up to 16 bytes of weak random " is not even
correct for Linux because there we will always read 16 bytes from
/dev/urandom and thus the whole theoretical attack won't work.  I'll
revise the description a bit.


Shalom-Salam,

   Werner

-- 
Die Gedanken sind frei.  Auschnahme regelt ein Bundeschgesetz.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]