Goetz Babin-Ebell wrote:

> But here the use of this uninitialized data is intentional
> and the programmer are very well aware of what they did.

The use of unititialized data in this case is stupid because the
entropy of this random data is close to zero.

The only sane way to deal with this it to either make it zero
or make it truely random.

Erik
-- 
-----------------------------------------------------------------
Erik de Castro Lopo
-----------------------------------------------------------------
"I would buy a Mac today if I was not working at Microsoft."
-- Senior Microsoft exective Jim Allchin in a 200 email to Bill
Gates : http://www.iowaconsumercase.org/010807/PLEX_7264.pdf
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       openssl-dev@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to