[1] NIST SP 800-90A Rev.1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators,NIST,2015,https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
[2] RFC 4086 Randomness Requirements for Security,IETF,2005,https://datatracker.ietf.org/doc/html/rfc4086
[3] Debian OpenSSL predictable PRNG issue (CVE-2008-0166) and related analyses,参见相关安全报告与学术论文
[4] FATF Guidance for a Risk-Based Approach to Virtual Assets and VASPs,FATF,2019,https://www.fatf-gafi.org/publications/fatfrecommendations/
[5] Enhancing Cross-border Payments: building blocks of a global roadmap,BIS/IMF/World Bank,2020,https://www.bis.org/publ/othp33.htm
[6] OWASP Mobile Top 10,OWASP,https://owasp.org/www-project-mobile-top-10/
[7] FIPS 140-3 Security Requirements for Cryptographic Modules,NIST,https://csrc.nist.gov/publications/detail/fips/140/3/final
评论
Alice
这篇分析很全面,特别是对随机数预测的对策讲得很实在,建议TP钱包尽快上线熵监控。
张强
希望能看到更多关于多重签名与阈签名实操案例,方便开发参考。
CryptoFan
支持公开审计和漏洞赏金,这样能提高信任度和透明度。
小米
关于新经币的合规部分写得很好,尤其是交易监测与名单筛查的建议。