Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 16 Jul 2000 13:29:50 -0700
From:      Mike Smith <msmith@freebsd.org>
To:        "Andrey A. Chernov" <ache@freebsd.org>
Cc:        markm@freebsd.org, current@freebsd.org
Subject:   Re: randomdev entropy gathering is really weak 
Message-ID:  <200007162029.NAA03949@mass.osd.bsdi.com>
In-Reply-To: Your message of "Sun, 16 Jul 2000 10:59:45 PDT." <20000716105943.A60072@freebsd.org> 

next in thread | previous in thread | raw e-mail | index | archive | help
> I found that I always got the same fortune quote after reboot, over and over 
> again. It means that /dev/random produce exact the same values after reboot.
> It means that machine timer or keyboard not used for enthropy gathering.
> Using keyboard alone not helps for automatic tasks because it can be even not 
> present, so machine timer must be used at least after reboot stage i.e. in 
> randomdev init procedure. Otherwise first random values are very predictable 
> and subject for attack.

The problem is that the randomdev stuff should be a delete option, ie. it 
should be built as part of the kernel unless EXPLICITLY excluded, not the 
wrong way around as it is at the moment.

-- 
... every activity meets with opposition, everyone who acts has his
rivals and unfortunately opponents also.  But not because people want
to be opponents, rather because the tasks and relationships force
people to take different points of view.  [Dr. Fritz Todt]




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-current" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200007162029.NAA03949>