Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
OpenSSL feeds your private key to the system PRNG (opensslrampage.org)
7 points by damncabbage on April 18, 2014 | hide | past | favorite | 1 comment


(There was no title for the post; please forgive my editorialising.)

In short, if there's not enough seed data in the system PRNG (or whatever random subsystem is hooked up), it dumps in your private key in an attempt to increase entropy.

Removed today: http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/cry...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: