Bug #3685
include PRNGFixes.java
Status: | Resolved | Start date: | 08/27/2014 | |
---|---|---|---|---|
Priority: | Immediate | Due date: | ||
Assignee: | - | % Done: | 0% | |
Category: | - | |||
Target version: | - | |||
Component: |
Description
The cryptographically secure random number generator exposed to Android through the Java Cryptography Architecture is not properly initialized on some older unpatched versions of Android. Google provides a PRNGFixes.java
class to force secure seeding of the CSRNG on all platform versions. This comment adds the PRNGFixes class & and a call to invoke the fixes from the FDroidApp class.
More detail is available from the Google Android Developers blogpost on the subject:
http://android-developers.blogspot.ca/2013/08/some-securerandom-thoughts.html
Related issues
Associated revisions
include PRNGFixes in Application.onCreate()
History
#1 Updated by Anonymous over 3 years ago
- Status changed from New to Resolved
Applied in changeset notecipher|commit:ae993855a070df642e6022e4c8431bbb798d544b.