Hacker News new | past | comments | ask | show | jobs | submit login
A good idea with bad usage: /dev/urandom (insanecoding.blogspot.com)
10 points by beefhash on April 13, 2016 | hide | past | favorite | 1 comment



This is from May 2014. Most of the concerns in this article were addressed in the getrandom syscall for Linux, proposed in July 2014:

https://lwn.net/Articles/606141/

The claims about /dev and chroots indicate that the author doesn't really have a coherent threat model -- chroots don't work that way, and any attacker who can subvert /dev can as easily subvert the application's binary itself, read the application's virtual memory and extract the private key, etc.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: