> - add new GRND_SECURE and GRND_INSECURE flags that have the actual > useful behaviors that we currently pretty much lack > > - consider the old 0-3 flag values legacy, deprecated, and unsafe > because they _will_ time out to fix the existing problem we have right > now because of their bad behavior. Just for the record because I did not see it mentioned in this thread, this patch by Andy Lutomirski, posted two weeks ago, adds GRND_INSECURE and makes GRND_RANDOM a no-op: https://lore.kernel.org/lkml/cover.1567126741.git.luto@xxxxxxxxxx/