Other Resources

  • The NIST FIPS 140 standard gives guidance for random numbers , particularly for testing their quality. The standard is on its second revision: FIPS 140-2. The first revision gave more detailed guidance on random number testing, so its still worth pursuing: http://csrc.nist.gov/cryptval/140-2.htm

  • The Entropy Gathering AND Distribution System (EGADS), primarily intended for systems without their own CRNGs and entropy gathering: www.securesoftware.com/resources/download_egads.html

  • RFC 1750: Randomness Recommendations for Security: www.ietf.org/rfc/rfc1750.txt

  • How We Learned to Cheat at Online Poker by Brad Arkin, Frank Hill, Scott Marks, Matt Schmid, Thomas John Walls, and Gary McGraw: www. cigital .com/papers/download/developer_gambling.pdf

  • Randomness and the Netscape Browser by Ian Goldberg and David Wagner: www.ddj.com/documents/s=965/ddj9601h/9601h.htm



19 Deadly Sins of Software Security. Programming Flaws and How to Fix Them
Writing Secure Code
ISBN: 71626751
EAN: 2147483647
Year: 2003
Pages: 239

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net