comment on why the securerandom.getinstancestrong() fallback is neither weaker nor reachable

This commit is contained in:
Craig Raw
2026-08-21 09:39:11 +02:00
parent 4e2903fe60
commit 9b05c26cf3
4 changed files with 7 additions and 1 deletions
+1 -1
Submodule drongo updated: 31130261ea...097420f6ea
@@ -62,6 +62,8 @@ public class MnemonicKeystoreEntryPane extends MnemonicKeystorePane {
try {
secureRandom = SecureRandom.getInstanceStrong();
} catch(NoSuchAlgorithmException e) {
//Not a fallback to a weaker source: both resolve to the SUN provider and the same java.base implementation seeded from the OS CSPRNG
//This branch is in any case unreachable, since securerandom.strongAlgorithms specifies DRBG:SUN, always present in the bundled runtime - see #2040
secureRandom = new SecureRandom();
}
@@ -168,6 +168,8 @@ public class MnemonicKeystoreImportPane extends MnemonicKeystorePane {
try {
secureRandom = SecureRandom.getInstanceStrong();
} catch(NoSuchAlgorithmException e) {
//Not a fallback to a weaker source: both resolve to the SUN provider and the same java.base implementation seeded from the OS CSPRNG
//This branch is in any case unreachable, since securerandom.strongAlgorithms specifies DRBG:SUN, always present in the bundled runtime - see #2040
secureRandom = new SecureRandom();
}
@@ -112,6 +112,8 @@ public class Bip39Dialog extends NewWalletDialog {
try {
secureRandom = SecureRandom.getInstanceStrong();
} catch(NoSuchAlgorithmException e) {
//Not a fallback to a weaker source: both resolve to the SUN provider and the same java.base implementation seeded from the OS CSPRNG
//This branch is in any case unreachable, since securerandom.strongAlgorithms specifies DRBG:SUN, always present in the bundled runtime - see #2040
secureRandom = new SecureRandom();
}