Exposing /dev/random in containers does not put the system entropy pool at risk. That claim is repeated twice in the paper, and is false.
e.g. http://www.onkarjoshi.com/blog/191/device-dev-random-vs-uran... or http://security.stackexchange.com/a/14293/37
But yes, since there's only one entropy pool, attackers can drain /dev/random, causing other programs that rely on /dev/random to block.
All I can say is: on newer kernels, attackers can still drain the pool by using the getrandom syscall, so unless you block that syscall, not mounting /dev/random does not increase the security.
Yes, that is what I was trying to say. I'll clarify it in a future version.
That's a good point, I'll include that! Thanks.