| |
| | [No title] |
 | | For example, with the 160 "standard" or the 160-A "standard", I wouldn't use Yarrow to generate a 256-bit Twofish key (unless you got 1/2 the key, waited for a reseed, then got the other 1/2 of the key, in which case you'd be okay). |
 | | The motivation presented in the yarrow paper for the limit min(2^n,2^(k/3)*Pg) is a) to prevent the block sized counter C from wrapping, and b) to make it unlikely that K will take on the same value twice. |
 | | Yarrow sucking entropy out of /dev/random seems no more secure to me than buffering all entropy in a 512-byte pool stirred with a good polynomial before hasing it into the fast pool. |
| www.cypherspace.org /adam/yarrow.txt (9157 words) |
|