[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: apg (was: Intent to Rewrite: pwgen)



On Fri, Jun 01, 2001 at 09:21:02PM +0200, Marc Haber wrote:
> >One note about apg is that since the sources use the CAST encryption
> >algorithm to do its random number generation (instead of relying on
> >/dev/random or some MD5 or SHA based scheme), apg would have to go
> >into non-US.
> 
> I wasn't aware of that. Thanks for pointing that out to me, it will be
> fixed in the version that I actually upload.
> 
> Do you think it would be a good idea to ask upstream to refrain from
> using CAST?

You can certainly ask.  There's no reason to use CAST; it wouldn't be
hard to build one based on SHA, or just simply read from /dev/urandom.

						- Ted



Reply to: