[liberationtech] Google confirms critical Android crypto flaw
Doug Chamberlin
chamberlin.doug at gmail.com
Thu Aug 15 10:46:48 PDT 2013
On Thu, Aug 15, 2013 at 1:23 PM, Maxim Kammerer <mk at dee.su> wrote:
> On Thu, Aug 15, 2013 at 7:33 PM, Doug Chamberlin
> <chamberlin.doug at gmail.com> wrote:
> > Are you really saying THOUSANDS have reviewed and maintain the RNG? For
> > real?
>
> You are right — I didn't take the possibility of useless
> tongue-in-cheek remarks into account when using that expression in
> order to support a technical argument. Why don't you check the 20-year
> commit history of the relevant code [1], make an educated guess wrt.
> reviewers/committers ratio, account for developer attrition rate, and
> return to us with a hopefully better estimate. Good luck!
>
> [1]
> https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/log/drivers/char/random.c
>
>
I count 44 people committed to random.c since 2005, several who are clearly
not statistical experts, so perhaps "dozens".
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.stanford.edu/pipermail/liberationtech/attachments/20130815/de55bdff/attachment.html>
More information about the liberationtech
mailing list