[#9382] the sign of a number is omitted when squaring it. -2**2 vs (-2)**2 — <noreply@...>

Bugs item #6468, was opened at 2006-11-03 17:25

9 messages 2006/11/03

[#9385] merge YARV into Ruby — SASADA Koichi <ko1@...>

Hi,

42 messages 2006/11/04
[#9405] Re: merge YARV into Ruby — "Kirill Shutemov" <k.shutemov@...> 2006/11/06

On 11/4/06, SASADA Koichi <ko1@atdot.net> wrote:

[#9406] Re: merge YARV into Ruby — Sylvain Joyeux <sylvain.joyeux@...4x.org> 2006/11/06

On Monday 06 November 2006 16:01, Kirill Shutemov wrote:

[#9417] Re: merge YARV into Ruby — Sean Russell <ser@...> 2006/11/06

On Monday 06 November 2006 10:15, Sylvain Joyeux wrote:

[#9428] Re: merge YARV into Ruby — "Kirill Shutemov" <k.shutemov@...> 2006/11/06

On 11/6/06, Sean Russell <ser@germane-software.com> wrote:

[#9402] fast mutexes for 1.8? — MenTaLguY <mental@...>

Many people have been using Thread.critical for locking because Ruby

24 messages 2006/11/06

[#9450] Bikeshed: No more Symbol < String? — Kornelius Kalnbach <murphy@...>

Hi ruby-core!

21 messages 2006/11/07
[#9452] Re: Bikeshed: No more Symbol < String? — Yukihiro Matsumoto <matz@...> 2006/11/07

Hi,

[#9493] Future Plans for Ruby 1.8 Series — URABE Shyouhei <shyouhei@...>

This week Japanese rubyists were talking about the future of ruby_1_8

13 messages 2006/11/09

[#9515] External entropy pool for random number generator — "Kirill Shutemov" <k.shutemov@...>

In the attachment patch which allow to use external entropy pool for

13 messages 2006/11/11
[#9522] Re: External entropy pool for random number generator — "Nobuyoshi Nakada" <nobu@...> 2006/11/13

Hi,

[#9554] Ruby 1.[89].\d+ and beyond. — Hugh Sasse <hgs@...>

I've been thinking about how version numbers are restricting what we can do.

30 messages 2006/11/16
[#9561] Re: Ruby 1.[89].\d+ and beyond. — Eric Hodel <drbrain@...7.net> 2006/11/16

[#9563] Re: Ruby 1.[89].\d+ and beyond. — Hugh Sasse <hgs@...> 2006/11/16

On Fri, 17 Nov 2006, Eric Hodel wrote:

[#9564] Re: Ruby 1.[89].\d+ and beyond. — Eric Hodel <drbrain@...7.net> 2006/11/16

On Nov 16, 2006, at 12:02 PM, Hugh Sasse wrote:

[#9571] Re: Ruby 1.[89].\d+ and beyond. — "Robert Dober" <robert.dober@...> 2006/11/19

On 11/16/06, Eric Hodel <drbrain@segment7.net> wrote:

[#9604] #ancestors never includes the singleton class (inconsistent) — <noreply@...>

Bugs item #6820, was opened at 2006-11-22 08:49

12 messages 2006/11/22
[#9618] Re: [ ruby-Bugs-6820 ] #ancestors never includes the singleton class (inconsistent) — Yukihiro Matsumoto <matz@...> 2006/11/25

Hi,

[#9629] Re: [ ruby-Bugs-6820 ] #ancestors never includes the singleton class (inconsistent) — Sylvain Joyeux <sylvain.joyeux@...4x.org> 2006/11/27

> It is supposed to. Singleton classes (or eigenclasses, if you want to

Re: External entropy pool for random number generator

From: khaines@...
Date: 2006-11-13 17:26:48 UTC
List: ruby-core #9535
On Sun, 12 Nov 2006, Kirill Shutemov wrote:

> In the attachment patch which allow to use external entropy pool for
> Kernel::rand.
>
> When entropy pool present and you run Kernel::rand it reads 4(should
> be more?) bytes from pool and use this value as random seed. When pool
> ends(EOF reached) it sets to nil.
>
> It can be useful for cryptography or for testing. For example:
>
> srand(File.open("/dev/random")) # use system entropy pool
> rand
> srand # use standart ruby's generator

This feels like something that is best left as an extension instead of a 
change to the Ruby core.

The Mersenne Twister produces a high quality random number stream for 
non-cryptographic purposes, and having the random number system for Ruby 
be simple and uncomplicated is nice.

If one needs random numbers for cryptographic purposes, it's trivial to 
read numbers from a system entropy pool if one needs that.  That has a lot 
of drawbacks if one needs a lot of randomness, though.

For most cryptographic uses or simulation uses where one needs independent 
streams of random numbers, the best bet is to use a PRNG, seeded with 
entropy from a pool like /dev/random, that is known to produce high 
quality, cryptographically secure streams of numbers.  Where OpenSSL is 
available, one can use the PRNG in it.  One can also use something like 
Crypt::ISAAC, which is a pure ruby implementation of the ISAAC algorithm 
(I have a much faster C version sitting here waiting for me to finally 
push a new release).

I think this sort of interface over /dev/random is best written as an 
extension as well, leaving the Ruby core alone.


Kirk Haines


In This Thread