[17622] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: /dev/random is probably not

daemon@ATHENA.MIT.EDU (Florian Weimer)
Fri Jul 8 15:24:15 2005

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: Florian Weimer <fw@deneb.enyo.de>
To: Jason Holt <jason@lunkwill.org>
Cc: "Charles M. Hannum" <root@ihack.net>, cryptography@metzdowd.com
Date: Sat, 02 Jul 2005 18:52:03 +0200
In-Reply-To: <Pine.LNX.4.63.0507012127150.19263@pl2.zayda.com> (Jason Holt's
	message of "Fri, 1 Jul 2005 21:36:47 +0000 (UTC)")

* Jason Holt:

> You may be correct, but readers should also know that, at least in Linux:
>
> /usr/src/linux/drivers/char/random.c:
>   * All of these routines try to estimate how many bits of randomness a
>   * particular randomness source.  They do this by keeping track of the
>   * first and second order deltas of the event timings.

I somewhat doubt that moving the mouse around slowly resulting in
about 800=A0entropy bits per second is an accurate estimate.  But I have
to admit that I haven't run statistical tests on the unmixed data,
which would be necessary to back up my claim that this figure is
grossly exaggerated.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post