"Why does ntpkeygen pass a low entropy ignored seed into SystemRandom?""

Eric S. Raymond esr at thyrsus.com
Wed Jan 4 05:15:58 UTC 2017


Mark Atwood <fallenpegasus at gmail.com>:
> Hi!
> 
> My friend Greg Rubin, who does security work for Amazon, took at quick look
> at NTPsec 0.9.6, and asks the following queston:
> 
> "Why does ntpkeygen pass a low entropy ignored seed into SystemRandom? It's
> ignored, so it doesn't matter, but it's the type of error which concerns
> me."
> 
> ..m

And the answer is: I'm not a crypto geek, and I did that conversion in a hurry 
while thinking about other things.  I'd take a patch...
-- 
		<a href="http://www.catb.org/~esr/">Eric S. Raymond</a>


More information about the devel mailing list