On Mon, 10 Jun 2013 10:28:41 -0400, Nick Mathewson <[email protected]>
wrote:
[...]
> Good thing we're only using the PRNG for DNS transaction ids.  Still,
> we should get a better PRNG eventually[*]
> 
> Patching this bug in 2.0 and 2.1.

Thanks.  Yeah, it could have been worse.  Hopefully the bug has not been
copied anywhere outside libevent with more serious implications.

> [*] (Oh hey look what I did in my spare time the other month:
> https://github.com/nmathewson/libottery .  But see all the caveats in
> the README.)

Nice stuff.  I'll have a read through it sometime (it's a nice way to get
familiar with ChaCha too).  Could this be a future (non-default) option for
evutil_secure_rng?

Thanks,
*Joe

***********************************************************************
To unsubscribe, send an e-mail to [email protected] with
unsubscribe libevent-users    in the body.

Reply via email to