|
|
|
|
|
by zamalek
4670 days ago
|
|
Agreed. This article is very one-sided, and after posting a calmly worded comment regarding Linus's standpoint[1] on his attitude, it was deleted. The article is simply link bait and is not professional journalism. That being said, I have more confidence in Linus's knowledge regarding /dev/random. Mostly because XOR in this context is secure: 1. XOR is an incredibly powerful encryption algorithm (not primitive); one of the best we have. The problem with XOR is that you MUST use a UNIQUE one time pad (that is the length of the data) for every message AND you need to be able to securely transmit that one time pad. AES CTR is effectively using AES to create a one time pad for XOR encryption, as an example. 2. The prior steps are effectively creating a irrecoverable OTP meaning that any malicious intent in RRAND is effectively encrypted away. [1]: http://marc.info/?l=linux-kernel&m=137391223711946&w=2 |
|