Re: strengthening /dev/urandom

From: Guy Macon (
Date: 09/01/04

Date: Tue, 31 Aug 2004 15:55:56 -0700

Mok-Kong Shen <> says...

>BTW, for practical purposes I would 'guess' that cases
>where one really 'objectively' needs lots of full (or
>extremely high concentration) entropy are fairly rare.
>Could someone kindly give a few examples where such true
>randomness couldn't be substituted with good pseudo-
>randomness, e.g. AES in CTR? Thanks.

I wouldn't venture to guess. I have been involved with
two crypto projects in my entire life, one of which
involved an OTP. In that case the crypto expert we hired
said that the only justification was that the customer
wanted it and didn't care about the cost - that an
off-he-shelf software-only system would have been fine.


