A good idea with bad usage: /dev/urandom
insanecoding.blogspot.com
insanecoding.blogspot.com
Edit: I'm eagerly awaiting the tptacek takedown of this article. Comments like "even a regular user can run: cat /dev/random > /dev/null & cat /dev/zero > /dev/random... entropy will be degraded" do not give me confidence in this guy's understanding of the systems involved. Same with his blatant misreading of RNDZAPENTCOUNT and RNDCLEARPOOL, which simple research[2] reveals only clears the entropy count and does nothing to the underlying entropy pool itself.
[1]: http://www.2uo.de/myths-about-urandom/
[2]: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.g...
EDIT I was confused.
Talk about looking for problems that don't exist!
I guess that mentality is good in a crypto developer, but he took it to unnecessary extremes.
EPERM mode requested creation of something other than a regular
file, FIFO (named pipe), or UNIX domain socket, and the caller
is not privileged (Linux: does not have the CAP_MKNOD
capability); also returned if the filesystem containing
pathname does not support the type of node requested.
Of course there is still the theoretical problem that you could be running in a chroot where some unprivileged user has write access to the root and/or /dev so that she can create symlinks or move files around there. I don't think that should be the responsibility of the library to defend against though; but the responsibility of whoever created that chroot dir...Randomness is much more interesting than that, and while it would make a lot more sense for the sake of classical mechanics, it cannot possibly be explained away so neatly according to Bell's Inequality.
I just didn't explicitly mention global variables because that will always remain a possibility that lurks over everything. Technically, we can never rule them out because it's possible that all the universe and all the events of universe were preordained by one massive global variable, without any particular rhyme or reason for rules and laws for mechanics of local behavior.
Now randomness doesn't really exist. When we humans see
something as random, it's only because we don't know or
understand all the details. Therefore, any perceived
randomness on your part is your inability to track all
the variables.
(The currently accepted explanation of) quantum mechanics says otherwise. The essence of quantum mechanics is not certainly but probability. But this annoyed even Einstein, who famously said "God does not throw dice". Einstein was (probably) wrong about this.Stephen Hawking says:
God does play dice with the universe. All the evidence
points to him being an inveterate gambler, who throws
the dice on every possible occasion. [1]
[1] http://www.hawking.org.uk/does-god-play-dice.htmlEverything else seems specious. If you are in an environment controlled by an attacker there is no case where you can reliably generate random numbers. Sure as an attacker that already has root access I could replace /dev/urandom with a link to /dev/zero, but why would I do that when I could just install a kernel module that silently sent me whatever real random seed I decided to give you or patch your process to send the keys that are the end product of that randomness to my self?