[39483] in Cypherpunks
Re: NYT on Netscape Crack
daemon@ATHENA.MIT.EDU (Thomas Grant Edwards)
Tue Sep 19 16:32:59 1995
Date: Tue, 19 Sep 1995 16:09:21 -0400 (EDT)
From: Thomas Grant Edwards <tedwards@Glue.umd.edu>
To: Eli Brandt <eli@UX3.SP.CS.CMU.EDU>
Cc: cypherpunks@toad.com
In-Reply-To: <9509191438.AA16172@toad.com>
On Tue, 19 Sep 1995, Eli Brandt wrote:
> It sounds as if Netscape thinks that public knowledge of the key
> generation is part of the problem. I hope somebody on the security
> team convinces management that entropy is more important than publicity.
No matter what they say in the press, I doubt it will take more than a few
weeks to reverse engineer the new RNG seeder and figure out where the data
comes from.
I am hoping it was more of a PR thing than a technical thing. I hope
that Netscape tells us their RNG seed so Cyperhpunks don't have to go to all
the trouble. If they tell us, we can let them know if it is a reasonable
mechanism or bogus.
-Thomas