[Cryptography] SP800-90A B & C
Bear
bear at sonic.net
Mon Nov 11 18:23:29 EST 2013
On Mon, 2013-11-11 at 21:18 +0000, dj at deadhat.com wrote:
> Part of my argument was that we can have both. The design must ensure that
> if designed to the spec without manipulation, it will offer secure random
> numbers.
But if we have no way of verifying that it is designed to the spec
without manipulation we have no way of verifying that any security
exists. I have a problem with that.
> The spec can allow that users can mix in their own sources to
> mitigate the issues that the former model raises.
And it must.
There absolutely must be a requirement for sources of entropy whose
nature and functioning are verifiable.
Bear
More information about the cryptography
mailing list