I don't know much at all about cryptography, but why aren't all the natural sources of entropy an adequate source of random numbers?
I don't know much at all about cryptography, but why aren't all the natural sources of entropy an adequate source of random numbers?
A busy webserver does this much more often than it can easily generate entropy for. So you have to take shortcuts. That's where a pseudo-random number generator comes in.
[0]: https://en.wikipedia.org/wiki/Hardware_random_number_generat...
(Edit: that is, the noise introduced in a circuit by the fact that it's not at absolute zero, e.g. Johnson noise. Not just gathering entropy from a temperature sensor reading or something like that.)
Also I believe that is where /dev/random might get some of its information from, but I'm not too sure.
If I had to hazard a guess, I'd say that this isn't often done simply because computers didn't typically have a lot of sensors until recently, and now you're likely to have a good-quality dedicated hardware random number generator built in, e.g. Intel's RDRAND instruction.
I thought it was done a lot, for example, in the Linux kernel: "The random number generator gathers environmental noise from device drivers and other sources into an entropy pool." [1]