Comment Re:Description of vulnerability (Score 1) 137
From a brief trawl of the Android sources, it looks like Android's new-and-shiny OpenSSL-based SecureRandom only seeds the OpenSSL random generator if you open a TLS socket. If you don't - you will be using an unseeded OpenSSL RNG.