Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bad solution for "use strong randomness" #10

Open
Sc00bz opened this issue May 28, 2019 · 0 comments
Open

Bad solution for "use strong randomness" #10

Sc00bz opened this issue May 28, 2019 · 0 comments

Comments

@Sc00bz
Copy link

Sc00bz commented May 28, 2019

LibreSSL's getentropy_urandom() calls gotdata() which checks if the data is not all zeros. If you are calling this for short random integers, then all zeros is a very possible random value.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant