Re: monitoring entropy

Raul Miller (rdm@test.legislate.com)
Tue, 14 Oct 1997 17:39:41 -0401


Ingo Molnar <mingo@pc7537.hil.siemens.at> wrote:
> user-space needs entropy only for things like PGP key generation or SSH
> key generation, so these restrictions do not look like to be a problem,
> and IMO they defeat all user-space pool-draining attacks.

Counterexample: ftp://koobera.math.uic.edu/pub/software/sigs-0.50.tar.gz
uses a lot of entropy for secret key generation.

-- 
Raul