Релиз VeraCrypt 1.24, форка TrueCrypt , opennews (??), 08-Окт-19

13. "Релиз VeraCrypt 1.24, форка TrueCrypt "  +1 +/
Сообщение от Аноним (13), 08-Окт-19, 10:46 
Увеличение менее качественной энтропии не всегда лучше, чем немного но качественной.

Мнение от криптоаналитика из


> Using the Jitter RNG core, the rngd provides an entropy source that feeds into the Linux /dev/random device if its entropy runs low. It updates the /dev/random entropy estimator such that the newly provided entropy unblocks /dev/random.

This is a red flag. Entropy doesn't run low.

I'm calling it now: Don't use VeraCrypt.

They made a very questionable decision based on the sort of ignorance that leads people to use /dev/random and haveged rather than RtlGenRandom (Windows), getrandom(2) (new Linux), or /dev/urandom (old Linux).

Cryptography engineering requires care and this sort of ignorance tends to undermine secure implementations.

30. "Релиз VeraCrypt 1.24, форка TrueCrypt "  +2 +/
Сообщение от Аноним (25), 08-Окт-19, 11:58 
Ну фиг знает, я увидел Systemd и сразу закрыл.
