Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

Re: suggesting passwds to users

Subject: Re: suggesting passwds to users
Date: Wed, 20 Apr 2005 14:01:25 -0400 (EDT)
Computers may not be capable of generating truly random data without external
inputs to use as a source of entropy, but it need not be user interaction. 
Radioactive decay, for instance, is random (as best we can tell), and there
are systems that you can buy that use the timing of radiologic measurements as
a source of entropy.

That said, in most environments poor user password management is a much bigger
threat than PRNG limitations.

- David Hunter

-----Original message from Saqib Ali-----
[snip]

No offense, but DUH!  Isn't it impossible for a computer to generate a
truly random number without user interaction (such as random mouse
movements to generate entropy, as gnupg asks the user to do when
generating pub/priv keypairs)?  Nevertheless, as your
pseudo-randomness tends toward zero you will hit a point that is
statistically acceptable.  Like when scientists agree that 1x10^-200
chance of occurence can reasonably be considered impossible.




<Prev in Thread] Current Thread [Next in Thread>