Who the christ is feeding the output of /dev/random for its use as a cryptographic function without checking that what they read is in fact NOT just a stream of zeroes? Because that's an outcome which can happen from any truly random number generator just by chance - its unlikely, but not unreasonable.
Comments
Who the christ is feeding the output of /dev/random for its use as a cryptographic function without checking that what they read is in fact NOT just a stream of zeroes? Because that's an outcome which can happen from any truly random number generator just by chance - its unlikely, but not unreasonable.
Hence debiasing and the like.
If they can make it look like a stream of zeros, they can make it look like a random stream which is actually a pseudo-random stream as well.
Also, they might leave some randomness in, but it can be a small enough amount of entropy that it would still render crypto keys vulnerable.
Doi. This is an obvious danger and I feel stupid for not putting two and two together.