Re: [PATCH RFC] Disable save-entropy in jails

看板FB_security作者時間12年前 (2013/12/26 03:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串8/11 (看更多)
On Tue, 24 Dec 2013 16:04:53 -0800 Xin Li wrote: > When reading from /dev/random, one essentially consumes entropy that > is fed into the random device, and eventually it would cause a reseed. Reads don't trigger reseeds in Yarrow. And both Yarrow and Fortuna are designed so this isn't a problem. In any case reads that aren't under the control of an unprivileged attacker make it harder to perform a state-extension attack, not easier. This kind of thing shouldn't be an issue for any non-blocking random device that isn't quite badly broken. If it were, it would be better to fix the device. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1Ikojkzm (FB_security)
討論串 (同標題文章)
文章代碼(AID): #1Ikojkzm (FB_security)