On Sat, Jan 08, 2005 at 10:46:17AM +0800, Enzo Michelangeli wrote:
> But that was precisely my initial position: that the insight on the
> internal state (which I saw, by definition, as the loss of entropy by the
> generator) that we gain from one bit of output is much smaller than one
> full bit. 

I think this last bit is untrue. You will find that the expected number
of states of the PRNG after extracting one bit of randomness is half of
the number of states you had before, thus resulting in one bit of
entropy loss.

