>You seem to be arguing that there will be no need to use the --random-source option after November. If so, that is incorrect in my view.
The argument is that if you're on a currently supported, non-EOL Linux OS, you will not have this issue after November (since at that point in time, the RHEL 6 will be past end of life).
>ELS versions receive critical security fixes and urgent bug fixes until the end of their support. They are used right up to end of support, or even beyond in some cases, although that is certainly not recommended.
ELS versions are considered past EOL, and past Maintenance Support I & II. They will not be supported for new installs, will be out of compliance for PCI DSS, HIPPA, almost all third party vendor software, will not be certified on new hardware, etc. They are past their ten year lifecycle.
https://endoflife.software/operating-systems/linux/red-hat-e...
https://access.redhat.com/support/policy/updates/errata/#Ext...
Of course the few people on RHEL 6 will have to use the additional --random-source option, but the amount of people that this affects is in the single percentage point, or less.
Nothing is stopping someone from spinning up RHEL 5 three years from now and running my original command.
My original statements and points stand true. You were originally wrong to think that shuf is cryptographically insecure. It's been cryptographically secure for quite a while now.