Subject: Re: arc4random(9)
To: None <itojun@iijlab.net>
From: Perry E. Metzger <perry@wasabisystems.com>
List: tech-security
Date: 05/29/2002 11:02:28
itojun@iijlab.net writes:
> >I understand your position, but I think the name is honestly a very
> >bad one.
> >What if we worked to get FreeBSD etc. to change the name, too?
> 
> 	i think it too late, just like good old "CREAT instead of CREATE"
> 	example.  it is way too widely deployed, it's not only for BSD but also
> 	in tons of thirdparty softwares, like pipermail, linux PAM, linux ipsec,
> 	apache2, and more.

If that is truly the case, it may be that we need to support the API
then for compatibility, but I'm not sure we should necessarily
encourage it, and we should certainly document that the underlying
algorithm might not remain RC4.

This also still begs the question of what the right APIs ought to be.


--
Perry E. Metzger		perry@wasabisystems.com
--
NetBSD: The right OS for your embedded design. http://www.wasabisystems.com/