Check out this very well-written "post-mortem" of a related bug that was fixed recently in Cryptocat: http://nakedsecurity.sophos.com/2013/07/09/anatomy-of-a-pseudorandom-number-generator-visualising-cryptocats-buggy-prng/ NK