tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: FreeBSD rnd bug



On 2/20/15 7:55 AM, Taylor R Campbell wrote:
> Yes, for cprng_strong.  However, statistical tests on the output of
> a cryptographic PRNG will not detect failure to seed it.  They will
> detect only catastrophic bugs in the PRNG itself.  (They will also
> sometimes spuriously fire, as is the nature of statistical tests on
> uniform random data.)

See Dilbert's tour of accounting:

  http://dilbert.com/strip/2001-10-25

:-)

Lewis


Home | Main Index | Thread Index | Old Index