On Thu, Sep 06, 2012 at 04:40:48PM -0700, Doug Barton wrote:
> It is way past time that you either demonstrate that your claim has
> merit, or stop making it.
Doug,
At this point what are you asking for?
* To run better_than_nothing() before feed_dev_random() with
${entropy_file}?
I addressed that in Message-ID: <20120906142816.GA13179@dragon.NUXI.org>,
jhb in <201209050944.38042.jhb@freebsd.org>, and RW in
<20120905021248.5a17ace9@gumby.homeunix.com>.
* To not run 'postrandom' to delete ${entropy_file}?
I addressed that in Message-ID: <20120906142816.GA13179@dragon.NUXI.org>
and <20120905203222.GA2920@dragon.NUXI.org>.
Our our own sys/dev/random/nehemiah.c follows this advice:
...
* key, IV and the data are all read directly from the hardware RNG.
* All of these are used precisely once.
*/
As does OpenBSD.
* To run 'ps' twice in better_than_nothing()?
I've addressed that in <20120906164514.GA14757@dragon.NUXI.org> &
<20120906224519.GB18953@dragon.NUXI.org>, and Ian Lepore in
<1346962976.59094.187.camel@revolution.hippie.lan>.
--
-- David (obrien@FreeBSD.org)
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"