Consider replacing math/rand with crypto/rand in snapd

Bug #1878307 reported by Prabhu Subramanian
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Snappy
Opinion
Undecided
Unassigned

Bug Description

https://github.com/snapcore/snapd/blob/master/randutil/rand.go#L28

As per the official documentation, crypto/rand should be used for security-sensitive work

Tags: crypto go snapd
Revision history for this message
Ian Johnson (anonymouse67) wrote :

Hi, we do use crypto/rand for various purposes, but there are specific situations where we don't need cryptographic random numbers and psuedo random numbers are suitable in snapd.

Changed in snappy:
status: New → Opinion
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.