Unsafe use of g_random_int()

Michael McConville mmcconville at mykolab.com
Sat Aug 22 13:26:16 EDT 2015

Eion Robb wrote:
> Here's a win32 func for you to use instead of /dev/urandom.
> Technically, we're still building to target win2k (even though our GTK
> is only XP or higher), but this patch only works on XP or higher.
> Don't know if that's an issue here, or whether bumping windows version
> requirements is outside of scope for a minor/micro build.

In regard to dropping it in 2.x.y: I can't imagine there are many win2k
users, but I don't know whether dropping platform support in
minors/micros is considered acceptable. Is anyone actually testing on
win2k? I.e. do we know that it still works?

More information about the security mailing list