Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment Re:Other private Mexican mobile phone services (Score 1) 110

Remember that the NSA is a tax-founded government agency, thus it's much more likely to assume that indeed everyone in America (I take it that you mean the United States version of America?) support what they do. At least most people voted for it, considering both parties are equally eager to keep NSA running.

Comment Re:Why is the industry still using pseudo-randoms? (Score 1) 183

Not necessarily, because to get a decent quality unbiased random stream of bits from a simple thermal noise circuit you have to massage it quite a bit. And it may very well be sensitive to external stimuli. For example, a hacker without full access to the device could still run up the CPU and GPU to max load just before you're supposed to generate your secret key, to control the zener temperature.

Not saying it isn't better, but that "it's complicated".

Comment Re:What about banking sites? (Score 1) 183

It is my understanding from reading the paper from the security researchers that SecureRandom() is also perfectly fine as long as the implementation does what it's supposed to. In this case, the implementation was buggy, so instead of 256 bits of state they got 56 bits, or something similar. Bits were discarded that shouldn't be.

Slashdot Top Deals

WARNING TO ALL PERSONNEL: Firings will continue until morale improves.

Working...