[Cryptech Tech] ubuntu for the win!

Russ Housley housley at vigilsec.com
Sat Feb 28 22:08:58 UTC 2015


Leif:

>>>> fwiw ndn has a polliate server on random.nordu.net fed by a pair of
>>>> idquantique optical quantum devices
>>>>> https://wiki.ubuntu.com/Security/Features#prng-cloud
>>> 
>>> and gchq has a polliate server ....
>> 
>> The pages says that it provides a secure way to seed the PRNG.  How?  It does not say how the authentication or trust relationships are handled.
> 
> you get what tls gives you
 
This is a great example of a web PKI failure.  One needs to be much more picky about potential sources for PRNG seed than TLS for random web pages.

Russ



More information about the Tech mailing list