Re: new /dev/random

From: Tom St Denis (
Date: 10/06/04

Date: Wed, 06 Oct 2004 07:48:50 -0400

Bill Unruh wrote:
> Another tactic is to keep making unsupported statements until the other
> side gives up. If they don't storm off in a huff.

What I'm getting pissed off at is that people will publicly call you on
things that they're not sure of [hmm seems like my ToorCon talk...].

> Again, what is a CSPRNG? (as opposed to a PRNG).

CSPRNG => Cryptographically Secure Pseudo Random Number Generator.

For example, Fortuna == CSPRNG, LFSR == PRNG

That should answer your question.

> And again, what is your concern?

My concern is that the gang here that have been giving JL a hard time
don't know shit about what they are talking about. For instance, the
fact that /dev/random is not an RNG [despite what Guy thinks]. I'm
still against blocking and entropy estimation as it's just a "warm
fuzzy" that makes software more complicated [hence more likely to be
insecurely implemented].


