it seems like people did find it, some reported it, were told it wasn't an issue, and they didn't follow up. others apparently found it and didn't report it because when they did previously they were bullied.

Replies (1)

Yeah, I've seen a couple such posts but am suspicious about them. Anyway, guess we'll get a better picture of things soon enough. I'll be curious to know the answer to this, as I'll be looking for security audit info in the future, and hope to better understand how solid their processes are for something like this (can you test quality of entropy without finding an explicit bug?), since I gather you can from things I've read here and there but have no clue how that works. Thanks