[Hampshire] OpenSSL in Debian is broken

Top Page

Reply to this message
Author: Peter Alefounder
Date:  
To: Hants LUG
Subject: [Hampshire] OpenSSL in Debian is broken

Hugo Mills <hugo@???> wrote:
>    Basically, Debian managed to introduce a bug into their OpenSSL
> packages a couple of years ago that made the "random" numbers it
> generates predictable.


Why are pseudo-random numbers used anyway? Is it beyond the wit of
man to devise a bit of hardware that would produce genuine random
numbers? I am not an electronic engineer, but I understand that a
Zener diode can be used to generate white noise. Perhaps one could
be incorporated into a USB device with electronics to turn the
noise into a stream of numbers that could be read as required, or
maybe, if random numbers are so important, some such circuitry
should become part of the standard architecture of PCs.

On the other hand, no doubt someone who does know about these
things can tell me why it's not practical...

Peter Alefounder.



      __________________________________________________________
Sent from Yahoo! Mail.
A Smarter Email http://uk.docs.yahoo.com/nowyoucan.html