predictable random number generator used in web browsers

RESOLVED DUPLICATE of bug 322529

Status

()

Firefox
Security
--
critical
RESOLVED DUPLICATE of bug 322529
8 years ago
8 years ago

People

(Reporter: Michael Gilbert, Unassigned)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

(URL)

(Reporter)

Description

8 years ago
User-Agent:       Midori/0.1.6 (X11; Linux; U; en-us) WebKit/532+
Build Identifier: 

hello,

it has been discovered that all of the major web browsers use a
predictable pseudo-random number generator (PRNG).  please see
reference [0]. the robust solution is to switch to a provably
unpredictable PRNG such as Blum Blum Shub [1,2].

[0] http://www.trusteer.com/temporary-user-tracking-in-major-browsers
[1] Lenore Blum, Manual Blum, and Michael Shub, "A Simple Unpredictable
Pseudo-Random Number Generator," SIAM Journal on Computing, volume 15,
pages 364-383, May 1986.
[2] http://rng.doesntexist.org/gmpbbs

Reproducible: Always

Updated

8 years ago
Status: UNCONFIRMED → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 322529
You need to log in before you can comment on or make changes to this bug.