Re: svn commit: r239598 - head/etc/rc.d

看板FB_security作者時間13年前 (2012/09/08 14:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串27/29 (看更多)
On Thu, Sep 06, 2012 at 01:03:25PM -0700, David O'Brien (@FreeBSD) wrote: > I already said an attacker could have a local login on the system. > That would give them full knowledge of the kenv output. > Same attacker can figure out the 'date' output from uptime, etc... Note that this flies somewhat in the face of my argument for 'postrandom' based on Schneier's writings on deleting the seed file after it used. Please remember this is for better_than_nothing(). I like Arthur's patch that avoids calling better_than_nothing() if we feed_dev_random() with ${entropy_file}. -- -- David (obrien@FreeBSD.org) _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1GIjypvE (FB_security)
討論串 (同標題文章)
文章代碼(AID): #1GIjypvE (FB_security)