|
|||||||||||
|
Re: ARC4 algorithm
From: Theo de Raadt <deraadt(at)cvs.openbsd.org>
Date: Tue Mar 11 2003 - 19:01:36 EST
OK, how's this for polite: It is used because it is not nearly as broken as you claim it to be. Perhaps you are reading different books than I am reading. Perhaps you are not aware that the code is using well documented workarounds. Secondly, we are not using replacements that are new and as yet not well researched. Thirdly, we are using ARC4 in places where it has specific values, and I would be utterly shocked to see you find us using it in a place where the flaws matter. Is using ARC4 in our random number generator a security flaw? Please describe exactly how, but when you do, please don't include me in the cc. I must thank you for your detailed analysis showing how we are using it wrong. Forever in your debt, Theo. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message Received on Tue Mar 11 19:10:23 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:29:52 EDT |
||||||||||
|
|||||||||||