Bug #3755

include PRNGFixes.java

Added by Anonymous over 3 years ago.

Status:ResolvedStart date:08/27/2014
Priority:ImmediateDue date:
Assignee:-% Done:

0%

Category:-
Target version:-
Component:

Description

The cryptographically secure random number generator exposed to Android through the Java Cryptography Architecture is not properly initialized on some older unpatched versions of Android. Google provides a PRNGFixes.java class to force secure seeding of the CSRNG on all platform versions. This comment adds the PRNGFixes class & and a call to invoke the fixes from the FDroidApp class.

More detail is available from the Google Android Developers blogpost on the subject:
http://android-developers.blogspot.ca/2013/08/some-securerandom-thoughts.html


Related issues

Copied from NoteCipher - Bug #3685: include PRNGFixes.java Resolved 08/27/2014

Also available in: Atom PDF