Re: [Lynx-dev] predictable PRNG used

From: Thomas Dickey
Subject: Re: [Lynx-dev] predictable PRNG used
Date: Sun, 5 Jul 2009 09:05:58 -0400 (EDT)

On Sat, 4 Jul 2009, Michael S. Gilbert wrote:


it has been discovered that all of the major web browsers use a
predictable pseudo-random number generator (PRNG).  please see
reference [0].  lynx is fairly basic, so it may not be affected, but it
would be useful to check nontheless.  thanks.

lynx isn't using any of the features that are mentioned _there_.

It uses random numbers for initializing SSL as well as for temporary filenames, and probably could be improved (though no one's suggested any concrete improvements that I recall).



Thomas E. Dickey

