Re: [Hampshire] OpenSSL in Debian is broken

Top Page

Reply to this message
Author: Adrian Bridgett
Date:  
To: Hampshire LUG Discussion List
CC: p_alefounder
Subject: Re: [Hampshire] OpenSSL in Debian is broken
On Wed, May 14, 2008 at 18:24:57 +0100 (+0100), Hugo Mills wrote:
[snip]
>    You can, I believe, buy USB HRNGs. You do need to have a daemon
> running which scrubs and verifies the randomness of the device, though


Indeed. I'm not sure whether they actually use the HRNG to reseed PRNG
occasionally in fact.

>    It's practical -- I suspect it's not terribly cost-effective.


In this business if they can save 0.1c they'll do so. Shame given how
much stuff needs crypto these days.

Adrian