frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Myths about /dev/urandom (2014)

https://www.2uo.de/myths-about-urandom/
14•signa11•1h ago

Comments

NooneAtAll3•45m ago
(2014)
ape4•37m ago
Ah, I wonder what's change since then.
vbezhenar•24m ago
Here's quote from the article:

> Note from 2024: This article was published on March 16th, 2014. It is still correct in its discussion of entropy and randomness, but the Linux kernel random number generator has been reworked several times since then and does not look like this anymore. Good news: the separation between /dev/urandom and /dev/random is practically gone.

My understanding is that on modern Linux system:

At early boot phases, /dev/random can still block, because not enough entropy has been seeded yet. /dev/urandom will not block, but the random data might be of poor quality and not suitable for crypto purposes. This happens very early in the boot, so probably it's not even possible to run user stuff at this time. At least on my laptop, the message "random: crng init done" gets logged almost instantly after boot and long before even initrd starts. Might be different for exotic platforms, I guess.

Once there was enough entropy seeded, both /dev/random and /dev/urandom works identically, they don't block and they return high quality random data. So for most userspace purposes, these files can be used interchangeably, one is not better than another.

mananaysiempre•12m ago
> Might be different for exotic platforms, I guess.

Short-lived isolated VMs (like might be used for CI) are one place where entropy can be a problem. The relevant definition of “platform” here is less about the CPU architecture and more about the environment.

xiphmont•32m ago
Half the entropy is trying to figure out which pieces of this article's text are supposed to be the silly falsehoods being corrected, and which pieces are just the second or third paragraph of a preceding 'Fact'. Deadpool is easier to follow.
sph•5m ago
This is a good place as any to ask, last time I didn't get any answer: has there ever been a serious Linux exploit from manipulating/predicting bad PRNG? Apart from the Debian SSH key generation fiasco from years ago, of course.

Having a good entropy source makes mathematical sense, and you want something a bit more "random" than a dice roll, but I wonder at which point it becomes security theatre.

Of all the possible avenues for exploiting a modern OS might have, I figure kernel PRNG prediction to be very, very far down the list of things to try.

throw0101c•4m ago
Original discussion from 2014:

* https://news.ycombinator.com/item?id=7359992

Also:

2020: https://news.ycombinator.com/item?id=22683627

2018: https://news.ycombinator.com/item?id=17779657

2017: https://news.ycombinator.com/item?id=13332741

2015: https://news.ycombinator.com/item?id=10149019

Computer-Use in Hermes Agent v2.0 [video]

https://www.youtube.com/watch?v=Gx2joHxUhgg
1•frabonacci•1m ago•0 comments

Turn a bare VPS into an operational fortress in 15 minutes and 1 command

https://github.com/rockballslab/vps-secure
1•rockballslab•2m ago•1 comments

The Nobel-Winning Psychologist Who Believed He Found the Secret to Happiness

https://www.nytimes.com/2026/05/12/opinion/decision-making-herbert-simon.html
1•mistersquid•3m ago•0 comments

EpicPencil – A Free Epic Pen Alternative for Windows, macOS and Linux

https://epicpencil.es/
2•cosminrusu•3m ago•0 comments

Cortex

2•vimal_kumar•4m ago•0 comments

We used an AI as a controlled probe of our alert documentation

https://glassmkr.com/blog/ai-controlled-probe-of-alert-docs
1•glassmkr•5m ago•0 comments

No "yes." Either "HELL YEAH " or "no."

https://sive.rs/hellyeah
1•dsego•7m ago•0 comments

What 262,715 regex questions on stack overflow haven't answered

https://iev.ee/blog/what-262715-regex-questions-havent-answered/
1•birdculture•7m ago•0 comments

Osiris-Rex

https://science.nasa.gov/mission/osiris-rex/
2•simonebrunozzi•9m ago•0 comments

PgGraph – Graph database superpowers for your existing Postgres data

https://docs.evokoa.com/pggraph
1•pella•9m ago•0 comments

Data Brokers Push Back Against California AI Audit Requirements

https://news.bloomberglaw.com/privacy-and-data-security/data-brokers-push-back-against-california...
1•1vuio0pswjnm7•10m ago•0 comments

Toilmeter – Xkcd 1205 with error rework, frustration, and maintenance

https://www.osbytes.io/tools/toilmeter
1•dlln•11m ago•0 comments

Show HN: Jira Desktop Unofficial – lightweight Jira wrapper built with Tauri

https://news.ycombinator.com/submit
1•cas8398•11m ago•0 comments

AI Alliance Launches Project Tapestry to Build Sovereign AI with Yann LeCun

https://thealliance.ai/blog/ai-alliance-launches-project-tapestry-to-build-a-collaborative-founda...
1•AI_Alliance•12m ago•0 comments

Do Job Postings Show Early Labor-Market Effects of AI?

https://libertystreeteconomics.newyorkfed.org/2026/05/do-job-postings-show-early-labor-market-eff...
1•jnord•12m ago•0 comments

Points are a weird and inconsistent unit of measure

https://buttondown.com/hillelwayne/archive/points-are-a-weird-and-inconsistent-unit-of/
1•danborn26•12m ago•0 comments

Ask HN: Who needs contributors? (May 2026)

1•Kathan2651•13m ago•0 comments

Cube: Wrapping Benchmarks Once, Unlocking Agentic AI for Everyone

https://thealliance.ai/blog/cube-wrapping-benchmarks-once-unlocking-agentic-ai-for-everyone
1•AI_Alliance•14m ago•0 comments

From night to noon: France's reactors are now bending for European solar

https://www.pv-magazine.com/2026/05/14/from-night-to-noon-frances-reactors-are-now-bending-for-eu...
1•ndr42•16m ago•0 comments

Sam Altman's Business Dealings Under GOP Scrutiny Ahead of OpenAI's IPO

https://www.wsj.com/tech/ai/sam-altmans-business-dealings-under-gop-scrutiny-ahead-of-openais-ipo...
2•1vuio0pswjnm7•17m ago•0 comments

EU social media ban could come this summer, von der Leyen says

https://www.politico.eu/article/eu-social-media-ban-could-come-this-summer-ursula-von-der-leyen-s...
2•speckx•19m ago•1 comments

Redwood Materials loses COO amid layoffs, restructuring

https://techcrunch.com/2026/04/23/redwood-materials-loses-coo-amid-layoffs-restructuring/
1•PaulHoule•20m ago•0 comments

What happens when you post a real Monet and say it's AI?

https://twitter.com/jediwolf/status/2054776716770320631
34•nailer•22m ago•4 comments

New York, California pension leaders oppose 'extreme' SpaceX control structure

https://www.reuters.com/legal/government/new-york-california-pension-leaders-oppose-extreme-space...
6•2OEH8eoCRo0•23m ago•0 comments

Why agentic coding makes the spec problem worse

https://www.bicameral-ai.com/blog/why-agentic-coding-makes-the-spec-problem-worse
1•jinhk•23m ago•0 comments

Productivity Lessons from Charlie Munger

https://selfmanager.ai/articles/top-productivity-lessons-learned-from-charlie-munger
1•marian_abz•24m ago•0 comments

Raycast v2 Beta released

https://www.raycast.com/new
1•dcas•25m ago•0 comments

Vantafort: GPU-native space domain awareness

https://vantafort.com/
1•jonbaer•25m ago•0 comments

The Secret Mission to Fly Taiwan's President to Africa

https://www.nytimes.com/2026/05/14/world/asia/taiwan-eswatini-china-flight.html
1•donohoe•28m ago•0 comments

Show HN: Git-Shitstorm: How to Make Any Developer Lose Their Mind

https://github.com/einenlum/git-shitstorm
1•Einenlum•28m ago•0 comments