Conversation

Oh my. Apparently, AMD CPUs will sometimes return bad results from RDRAND after a suspend. That's bad, but if everyone has been following the cryptographer's advice and _just used getrandom()_ that's not a problem. ... nope! systemd of course didn't!
16
581
Oh, that's why. Because the entropy bowl might be empty! The amount of damage the Linux kernel might have made by convincing everyone entropy somehow magically runs out is incalculable.
Image
6
216
Replying to
There has been so much contradicting info on /dev/urandom vs. /dev/random, and I am just recently learning that I can actually use urandom for stuff that really needs to be random. The blocking behaviour of /dev/random hints that its entropy is better quality and thus for crypto
3
11