Ted Unangst <tedu <at> tedunangst.com> writes:

> Any system that actually uses egd is so hopelessly broken you
> are better off just turning around and walking away. No software in
> 2014 should be using egd; no software in 2014 should support using egd
> by accident.

This is wrong. The egd protocol is acceptable for getting random
bytes from a device not directly talked to by the kernel, such as
the Simtec entropyKey (either directly or via network), to applications
in cases where it is not possible to add these bytes to the kernel pool
(rare but possible especially in hosted scenarios).

Of course the data from egd should only ever be used mixed with kernel-
provided entropy…

bye,
//mirabilos

Reply via email to