logoalt Hacker News

Brybry • yesterday at 6:47 PM • 2 replies • view on HN

Are you saying to take a hash of a picture and convert that to base 6 for your dice rolls to plug into a word list for creating a passphrase?

Is that actually better (in practice, not in terms of entropy) than /dev/urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.


Replies

lisper • yesterday at 7:05 PM

> Is that actually better (in practice, not in terms of entropy) than /dev/urandom?

It offers protection in the event that your /dev/urandom is compromised. Otherwise no.

(Of course, if your /dev/urandom is compromised then whatever process you use to compute a hash of a photo is likely compromised as well.)

Matumio • yesterday at 7:12 PM

If you're concerned about that, you can concat your JPEG with a few bytes from /dev/random and you'll get the security of whichever is stronger. In practice none of this will be your weakest link.

➕ show 1 reply