Random Fail
I must be out of the security loop. I first learned about the latest random number bug via a cartoon . Schneier has a short summary of the problem. This is very disturbing because it went unnoticed since September of 2006 in a number of Linux distributions. Both SSL certificates and SSH keys generated on these systems are affected. This reminds me of a paper I wrote on a similarly weak RNG in Kerberos , with Steve Lodin and Gene Spafford 11 years ago. In the case of Kerberos Version 4, it used a RNG that depended only about 20 bits of entropy. The maintainers of Kerberos knew it was weak and implemented a much stronger one for Kerberos Version 5 and backported the new RNG to Version 4. However, the old RNG code was left in the source tree and due to a somewhat convoluted Makefile and source code, the new RNG was never called. The failure was masked by the existence of the old, weaker RNG code. While working at Sun Microsystems, on the groundbreaking, but commercially unsuccessfu...