From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Jean Louis Newsgroups: gmane.emacs.help Subject: About randomity, entropy, random passwords - was Re: Noob dumb question (extending emacs) Date: Mon, 25 Oct 2021 22:54:35 +0300 Message-ID: References: <87y26kkuag.fsf@web.de> <875ytnucjn.fsf@web.de> <87sfwqre9e.fsf@web.de> <8735opa2e8.fsf@web.de> <87tuh5fdha.fsf@web.de> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="40033"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Mutt/2.0.7+183 (3d24855) (2021-05-28) To: help-gnu-emacs@gnu.org Original-X-From: help-gnu-emacs-bounces+geh-help-gnu-emacs=m.gmane-mx.org@gnu.org Mon Oct 25 21:56:57 2021 Return-path: Envelope-to: geh-help-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1mf65P-0009px-Ss for geh-help-gnu-emacs@m.gmane-mx.org; Mon, 25 Oct 2021 21:56:47 +0200 Original-Received: from localhost ([::1]:57640 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1mf65O-0001aW-Ms for geh-help-gnu-emacs@m.gmane-mx.org; Mon, 25 Oct 2021 15:56:46 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:51608) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1mf64l-0001XY-3j for help-gnu-emacs@gnu.org; Mon, 25 Oct 2021 15:56:07 -0400 Original-Received: from stw1.rcdrun.com ([217.170.207.13]:48493) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1mf64i-0005AA-Pn for help-gnu-emacs@gnu.org; Mon, 25 Oct 2021 15:56:06 -0400 Original-Received: from localhost ([::ffff:41.75.189.151]) (AUTH: PLAIN admin, TLS: TLS1.3,256bits,ECDHE_RSA_AES_256_GCM_SHA384) by stw1.rcdrun.com with ESMTPSA id 0000000000027F1D.0000000061770BD2.00004535; Mon, 25 Oct 2021 12:56:02 -0700 Mail-Followup-To: help-gnu-emacs@gnu.org Content-Disposition: inline In-Reply-To: <87tuh5fdha.fsf@web.de> Received-SPF: pass client-ip=217.170.207.13; envelope-from=bugs@gnu.support; helo=stw1.rcdrun.com X-Spam_score_int: -13 X-Spam_score: -1.4 X-Spam_bar: - X-Spam_report: (-1.4 / 5.0 requ) BAYES_00=-1.9, PDS_BTC_ID=0.499, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: help-gnu-emacs@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Users list for the GNU Emacs text editor List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: help-gnu-emacs-bounces+geh-help-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "help-gnu-emacs" Xref: news.gmane.io gmane.emacs.help:134157 Archived-At: * Michael Heerdegen [2021-10-25 16:22]: > Jean Louis writes: > > > Do you say you can predict outcome of my `rcd-password' function? > > Yes, I said I can predict the outcome using unlimited trials. > > > Send contract, I sign it. > > Cool! > > How do you plan to test whether your password is in my trials? You will > receive a lot of trials, and I want to be sure you don't cheat. Because > it will take some time. Hey... but I am not going to spend time checking terrabytes of your trials. You have got unlimited trials that you do on yourside, not that I work for you and finally pay you for my work. That is called brute force. Not an algorithm that breaks the function and predicts its outcome. Emacs Lisp function `random' is quite handy and definitely not random enough as such. But with little support of Emacs Lisp it becomes very random. The matter is solved by providing a new seed. If seed is pretty random, then `random' becomes random. Here is enough entropy that it can generate random passwords: (defun rcd-random-md5-string () (md5 (concat (emacs-uptime) (format-time-string "%N %6N %3N")))) (rcd-random-md5-string) ⇒ "37c981115ec8cd7455667e1ad57e894b" (defun rcd-password-generate-1 (string) "Return capitalized or downcased single symbol from a string" (random (rcd-random-md5-string)) (let* ((max (length string)) (rnd (random max)) (single (substring string rnd (+ rnd 1)))) single)) (rcd-password-generate-1 "!@#$%^&*()-=+_[]{}|)ABCDEFGHIJKLMNOPQRSTUVWHYZ") ⇒ "Y" (rcd-password) ⇒ "wqg9@avJ@fErcvI4rrKt" Good enough for websites, system accounts, chat accounts, etc. -- Jean Take action in Free Software Foundation campaigns: https://www.fsf.org/campaigns In support of Richard M. Stallman https://stallmansupport.org/