On Mon, 19 Jul 1999, Ben Laurie wrote:

> > The brief summary of the above is that it's possible to simply replace
> > /dev/random with something which doesn't deplete entropy and the problem
> > will go away. And yes, it is possible to do that in a secure manner.
> 
> So what you are saying is that you'd be happy to run your server forever
> on an inital charge of 128 bits of entropy and no more randomness ever?
> 
> Really?

Well, I simplified a bit - it's a good idea to mix in more entropy
whenever it's available just for good measure, and pool it to be
introduced in large enough chunks to prevent continuation attacks, but the
short answer is yes.

-Bram

Reply via email to