lynx-dev
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Lynx-dev] predictable PRNG used


From: Thomas Dickey
Subject: Re: [Lynx-dev] predictable PRNG used
Date: Sun, 5 Jul 2009 09:05:58 -0400 (EDT)

On Sat, 4 Jul 2009, Michael S. Gilbert wrote:

hello,

it has been discovered that all of the major web browsers use a
predictable pseudo-random number generator (PRNG).  please see
reference [0].  lynx is fairly basic, so it may not be affected, but it
would be useful to check nontheless.  thanks.

lynx isn't using any of the features that are mentioned _there_.

It uses random numbers for initializing SSL as well as for temporary filenames, and probably could be improved (though no one's suggested any concrete improvements that I recall).


mike

[0] http://www.trusteer.com/temporary-user-tracking-in-major-browsers


_______________________________________________
Lynx-dev mailing list
address@hidden
http://lists.nongnu.org/mailman/listinfo/lynx-dev


--
Thomas E. Dickey
http://invisible-island.net
ftp://invisible-island.net




reply via email to

[Prev in Thread] Current Thread [Next in Thread]