Skip to content

Comment on Linus on /dev/random: "We actually know what we are doing. You don't."parent

Comments

"The attack can't use external input e.g. clock because the NSA can't correlate generating the random number with seeing it in flight."

It could potentially use the number of milliseconds since the last hour, or maybe the state of the branch predictor, or any number of other things that have exploitable biases (with NSA resources, 1/1000000000 is pretty good odds).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.