I guess it's working...;^(  

sorry folks to disturb you all...

-Ed

-----Original Message-----
From: Ed Sanborn 
Sent: Wednesday, September 04, 2002 11:39 AM
To: [EMAIL PROTECTED]
Subject: RE: openssl Newbie ( PRNG seed )


Hi Rich,

  Any chance you can help me?  I am testing my outbound email.
Can you please reply to me so that I can see if my message
made it to you?

Thanks,

        Ed

-----Original Message-----
From: Rich Salz [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, September 04, 2002 11:27 AM
To: [EMAIL PROTECTED]
Subject: Re: openssl Newbie ( PRNG seed )


>>    "How important is the PRNG seed to the 
>>    total security of your program ?"

How quickly they forget... :(

Your SSL connections can be broken.  Several years ago Netscape used a 
poor random seed (like getpid() or'd into the time() or some such), and 
Dave Wagner (et al) at Berkeley were able to completely decode the SSL 
traffic.

Don't do this.  Don't do this.  Do not do this.
        /r$

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to