Goetz Babin-Ebell wrote: > But here the use of this uninitialized data is intentional > and the programmer are very well aware of what they did.
The use of unititialized data in this case is stupid because the entropy of this random data is close to zero. The only sane way to deal with this it to either make it zero or make it truely random. Erik -- ----------------------------------------------------------------- Erik de Castro Lopo ----------------------------------------------------------------- "I would buy a Mac today if I was not working at Microsoft." -- Senior Microsoft exective Jim Allchin in a 200 email to Bill Gates : http://www.iowaconsumercase.org/010807/PLEX_7264.pdf ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager [EMAIL PROTECTED]