Bug #3685
include PRNGFixes.java
| Status: | Resolved | Start date: | 08/27/2014 | |
|---|---|---|---|---|
| Priority: | Immediate | Due date: | ||
| Assignee: | - | % Done: | 0% | |
| Category: | - | |||
| Target version: | - | |||
| Component: |
Description
The cryptographically secure random number generator exposed to Android through the Java Cryptography Architecture is not properly initialized on some older unpatched versions of Android. Google provides a PRNGFixes.java class to force secure seeding of the CSRNG on all platform versions. This comment adds the PRNGFixes class & and a call to invoke the fixes from the FDroidApp class.
More detail is available from the Google Android Developers blogpost on the subject:
http://android-developers.blogspot.ca/2013/08/some-securerandom-thoughts.html
Related issues
Associated revisions
include PRNGFixes in Application.onCreate()
History
#1 Updated by Anonymous over 3 years ago
- Status changed from New to Resolved
Applied in changeset notecipher|commit:ae993855a070df642e6022e4c8431bbb798d544b.