看板 FB_security 關於我們 聯絡資訊
On Thu, Sep 06, 2012 at 11:01:57PM +0100, RW wrote: > On Thu, 6 Sep 2012 10:42:47 -0700 David O'Brien wrote: > > On Wed, Sep 05, 2012 at 08:07:54AM +1000, Peter Jeremy wrote: > > > >What if, instead of replacing /entropy, we add an additional file > > > >in /var/db/entropy at boot time that is numerically 1 higher than > > > >$entropy_save_num ? > > > That sounds like a reasonable idea. > > > > I don't see what that adds or fixes. It does not correct the > > possible reuse of seed material. > > Reusing a secure entropy file is only a problem if the complete history > of yarrow, from boot until some significant output, is exactly the same > as on a previous boot. I feel this is discussed in the yarrow and Fortuna papers. Please provide specific section reference backing your position for me to read. Why are we trying to invent a new shiny way to address an issue discussed by yarrow's author? What is your specific argument against deleting the consumed seed file? Do you feel the 4k bytes of /entropy is too little? -- -- David (obrien@FreeBSD.org) _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"