From owner-freebsd-security@FreeBSD.ORG Sun Sep 16 13:46:53 2012 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 69CB6106566C; Sun, 16 Sep 2012 13:46:53 +0000 (UTC) (envelope-from des@des.no) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id 1B3378FC0C; Sun, 16 Sep 2012 13:46:52 +0000 (UTC) Received: from ds4.des.no (smtp.des.no [194.63.250.102]) by smtp.des.no (Postfix) with ESMTP id 0F3986591; Sun, 16 Sep 2012 15:46:52 +0200 (CEST) Received: by ds4.des.no (Postfix, from userid 1001) id C1D7A814A; Sun, 16 Sep 2012 15:46:51 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Mark Murray References: <50453686.9090100@FreeBSD.org> <20120911082309.GD72584@dragon.NUXI.org> <504F0687.7020309@FreeBSD.org> <201209121628.18088.jhb@freebsd.org> <5050F477.8060409@FreeBSD.org> <20120912213141.GI14077@x96.org> <20120913052431.GA15052@dragon.NUXI.org> Date: Sun, 16 Sep 2012 15:46:51 +0200 In-Reply-To: (Mark Murray's message of "Fri, 14 Sep 2012 22:49:14 +0100") Message-ID: <86fw6iyt9w.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.4 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: Arthur Mesh , Ian Lepore , Doug Barton , Ben Laurie , freebsd-security@freebsd.org, RW , "Bjoern A. Zeeb" , Mark Murray Subject: Re: svn commit: r239569 - head/etc/rc.d X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Sep 2012 13:46:53 -0000 Mark Murray writes: > You have to rely on something; Yarrow needs some entropy to cold-start, > and on a freshly installed OS, this is rocking-horse shit. This is > where BIG problems start because it is at this time that (eg) SSH keys > are built. We make some effort to get the user to "kayboard bash", but > experience has shown that annoyed users screw up, and annoyed engineers > are often worse. Look at the code, the "keyboard bash" hasn't worked since someone broke it in 2006. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no