However much I love the idea of people coding in more randomness, I'd get a
better fuzzy feeling if somebody with some cred in the crypto world was sitting
in on this discussion and commenting on the ideas.

Things like 'going out on the network and fetching some random bits via http'
are so utterly bogus (open to attack, presume networks are there) that they
kinda suggest this hasn't been well thought out. Likewise embedding a
dependency on keyboard/mouse movements. IIRC There have been articles making it
plain that week initial random settings propagate out like topsy: you can't
add trustable randomness by taking skewed input sources.

People like Bruce Schneier, Steve Bellovin, they are not unapproachable. Could
somebody mail them for comments on whats considered acceptable sources of
random bits?


