看板 FB_security 關於我們 聯絡資訊
On Thu, Sep 06, 2012 at 04:40:48PM -0700, Doug Barton wrote: > It is way past time that you either demonstrate that your claim has > merit, or stop making it. Doug, At this point what are you asking for? * To run better_than_nothing() before feed_dev_random() with ${entropy_file}? I addressed that in Message-ID: <20120906142816.GA13179@dragon.NUXI.org>, jhb in <201209050944.38042.jhb@freebsd.org>, and RW in <20120905021248.5a17ace9@gumby.homeunix.com>. * To not run 'postrandom' to delete ${entropy_file}? I addressed that in Message-ID: <20120906142816.GA13179@dragon.NUXI.org> and <20120905203222.GA2920@dragon.NUXI.org>. Our our own sys/dev/random/nehemiah.c follows this advice: ... * key, IV and the data are all read directly from the hardware RNG. * All of these are used precisely once. */ As does OpenBSD. * To run 'ps' twice in better_than_nothing()? I've addressed that in <20120906164514.GA14757@dragon.NUXI.org> & <20120906224519.GB18953@dragon.NUXI.org>, and Ian Lepore in <1346962976.59094.187.camel@revolution.hippie.lan>. -- -- David (obrien@FreeBSD.org) _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"