Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.python > #7171

Re: How good is security via hashing

Path csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!feeder.news-service.com!newsfeed.xs4all.nl!newsfeed6.news.xs4all.nl!xs4all!post.news.xs4all.nl!not-for-mail
Return-Path <python-python-list@m.gmane.org>
X-Original-To python-list@python.org
Delivered-To python-list@mail.python.org
X-Spam-Status OK 0.000
X-Spam-Evidence '*H*': 1.00; '*S*': 0.00; '*not*': 0.05; 'modified': 0.05; 'terry': 0.07; 'wrapper': 0.07; '(sorry,': 0.09; 'received:80.91': 0.09; 'received:80.91.229': 0.09; 'received:80.91.229.12': 0.09; 'received:gmane.org': 0.09; 'received:list': 0.09; 'received:lo.gmane.org': 0.09; 'am,': 0.14; 'wrote:': 0.14; '3.3.': 0.16; '7:35': 0.16; 'ctypes.': 0.16; 'predictable': 0.16; 'reedy': 0.16; 'subject:security': 0.16; 'guess': 0.19; 'jan': 0.20; 'header:In-Reply-To:1': 0.21; 'so.': 0.22; 'url:wiki': 0.23; 'library.': 0.25; 'modules': 0.26; "i'm": 0.27; 'random': 0.28; "python's": 0.29; 'subject:How': 0.30; 'one)': 0.30; "skip:' 10": 0.32; 'header:X-Complaints-To:1': 0.32; 'to:addr:python-list': 0.33; 'asking': 0.33; 'header:User- Agent:1': 0.35; 'using': 0.35; 'sequence': 0.37; 'url:en': 0.37; 'received:org': 0.38; 'url:org': 0.38; 'subject:: ': 0.38; 'should': 0.39; 'header:Mime-Version:1': 0.39; 'to:addr:python.org': 0.39; 'generate': 0.60; 'forget': 0.61; 'url:secure': 0.73; 'robin': 0.84; 'url:wikimedia': 0.84; 'subject:good': 0.93
X-Injected-Via-Gmane http://gmane.org/
To python-list@python.org
From Terry Reedy <tjreedy@udel.edu>
Subject Re: How good is security via hashing
Date Tue, 07 Jun 2011 14:26:14 -0400
References <4DEDFAEB.4050006@chamonix.reportlab.co.uk> <BANLkTinRJpe6zQ5EYVYXxjfc+ue=Gh-4JA@mail.gmail.com> <4DEE0CF9.6020508@chamonix.reportlab.co.uk>
Mime-Version 1.0
Content-Type text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding 7bit
X-Gmane-NNTP-Posting-Host rain.gmane.org
User-Agent Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.17) Gecko/20110414 Lightning/1.0b2 Thunderbird/3.1.10
In-Reply-To <4DEE0CF9.6020508@chamonix.reportlab.co.uk>
X-BeenThere python-list@python.org
X-Mailman-Version 2.1.12
Precedence list
List-Id General discussion list for the Python programming language <python-list.python.org>
List-Unsubscribe <http://mail.python.org/mailman/options/python-list>, <mailto:python-list-request@python.org?subject=unsubscribe>
List-Archive <http://mail.python.org/pipermail/python-list>
List-Post <mailto:python-list@python.org>
List-Help <mailto:python-list-request@python.org?subject=help>
List-Subscribe <http://mail.python.org/mailman/listinfo/python-list>, <mailto:python-list-request@python.org?subject=subscribe>
Newsgroups comp.lang.python
Message-ID <mailman.2537.1307471185.9059.python-list@python.org> (permalink)
Lines 16
NNTP-Posting-Host 82.94.164.166
X-Trace 1307471185 news.xs4all.nl 49175 [::ffff:82.94.164.166]:57127
X-Complaints-To abuse@xs4all.nl
Xref x330-a1.tempe.blueboxinc.net comp.lang.python:7171

Show key headers only | View raw


On 6/7/2011 7:35 AM, Robin Becker wrote:

> I guess what I'm asking is whether any sequence that's using random to
> generate random numbers is predictable if enough samples are drawn.

Apparently so. random.random is *not* 'cryptographically secure'.
https://secure.wikimedia.org/wikipedia/en/wiki/Cryptographically_secure_pseudorandom_number_generator

One of Python's crypto wrapper modules (sorry, forget which one) was 
recently modified to expose the crypto rng functions in the wrapped C 
library. It should be mentioned in What New for 3.3. You might be able 
to get at the same functions with ctypes.

-- 
Terry Jan Reedy

Back to comp.lang.python | Previous | Next | Find similar | Unroll thread


Thread

Re: How good is security via hashing Terry Reedy <tjreedy@udel.edu> - 2011-06-07 14:26 -0400

csiph-web