[hafqa] [hafqa] [Bug 2770] /dev/urandom produces predicatble data just after boot

From: bugzilla-daemon at maemo.org bugzilla-daemon at maemo.org
Date: Sun Jun 15 00:26:58 EEST 2008
https://bugs.maemo.org/show_bug.cgi?id=2770


bugzilla770 at nmacleod.com changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |aklapper at openismus.com,
                   |                            |bugzilla770 at nmacleod.com
           Severity|normal                      |critical
           Priority|Medium                      |High




------- Comment #6 from bugzilla770 at nmacleod.com  2008-06-15 00:26 GMT+3 -------
This seems quite bad to me - I wonder if it could also affect SSL/TLS in the
browser, meaning that encrypted sessions might also be using weak/predictable
keys... while I doubt anyone is going to have their devices hacked due to the
existance of weak keys (not very popular etc.) it's a potential problem that
could be exploited in future.

I'm going to take the liberty of raising the severity of this bug as IMHO it
needs attention - anyone from Maemo/Nokia can knock it back down if/when they
respond, this bug has been open almost 6 months... I'll also CC Andre the
bugmaster. :)


-- 
Configure bugmail: https://bugs.maemo.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug, or are watching the QA contact.

More information about the hafqa mailing list