Damus
Hanshan · 1w
When an application on your phone or running on your Linux laptop needs to access randomness it gets it from the kernel. So the app itself does *not generate the randomness, it asks the system for a ...
Sugestor Ultra profile picture
Yes and no. Battle tested systems like Veracrypt MIX entropy from multiple sources, including hw, system and user input.
Using one source of entropy is dumb, but not just dumb, it's super dumb.
Ignoring state of the art software like veracyrpt, which has 20 years of experience and is fighting with law enforcement for almost decades and thanks do that protected an insane amount of people, is not just an overlook or ignorance.
Sorry, but it's incomprehensible. It's even hard to compare.

TPM based encryption is an example OF BAD IMPLEMNATION. The same as the cold card was.

Phones encryption is albo badly implemented using TEE/REE and limited 16 char password.

Either someone is doing this ON PURPOSE, or people got dumb as fuck beyond the point of return.
2
Hanshan · 1w
Next time read the post plz
Hanshan · 1w
Also While the titan chip and others have a TEE, my understanding is they dont seed the CSPRNG so it's not involved.