On Thu, Dec 23, 2010 at 11:39:59AM +0100, Kurt Knochner wrote: > 2010/12/22 Marsh Ray <[email protected]>: > > In any case, generic statistical tests might detect really horrible > > brokenness but they're are not the thing to certify CSRNGs with. > > Really? So, how do you certify the IMPLEMENTATION (bold, not shouting) > of a CSRNG, (not the theoretical design)?
There's no really good way to do this at the moment. Yes, that's a
problem.
Joachim
