Do not use GnuPG under Mac OS RNG

Gordon Worley redbird@mac.com
Wed Jun 27 15:42:02 2001


First off, sorry I missed this discussion when it was getting going, 
since my domain name is down at the moment and I'm sending from this 
mac.com address.  Anyway...

Okay, first, let's make sure we're talking about the same thing. 
rndunix is what I'm getting if I call rnd(), correct?  I assumed 
that's what you meant, but I thought I'd better check.  If this is 
it, yes, the patterns are horrible, often generating alternative odd 
and even numbers and such other obvious patterns.

Secondly, egd claims to be collecting from 21 sources on my machine. 
If rndunix is just one of those, won't the entropy from the other 
sources take care of this?

Finally, thank you to pplf, who apparently saw my notice on the Mac 
GPG web site that my e-mail was down and forwarded this to me. 
Please, cc me in the rest of this discussion, because I don't really 
want to be signed up twice to the list (vix. I'm assuming that my 
domain name will be up again soon).
-- 
Gordon Worley
http://macgpg.sourceforge.net/
mailto:redbird@mac.com
PGP Fingerprint:  C462 FA84 B811 3501 9010  20D2 6EF3 77F7 BBD3 B003