From owner-freebsd-security@FreeBSD.ORG Fri Sep 14 19:25:08 2012 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id CE6FD1065679 for ; Fri, 14 Sep 2012 19:25:08 +0000 (UTC) (envelope-from markm@FreeBSD.org) Received: from gromit.grondar.org (grandfather.grondar.org [IPv6:2a01:348:0:15:5d59:5c20:0:2]) by mx1.freebsd.org (Postfix) with ESMTP id 7D88D8FC19 for ; Fri, 14 Sep 2012 19:25:08 +0000 (UTC) Received: from uucp by gromit.grondar.org with local-rmail (Exim 4.77 (FreeBSD)) (envelope-from ) id 1TCbVj-0004vy-Ml for freebsd-security@freebsd.org; Fri, 14 Sep 2012 20:25:07 +0100 Received: from localhost ([127.0.0.1] helo=groundzero.grondar.org) by groundzero.grondar.org with esmtp (Exim 4.77 (FreeBSD)) (envelope-from ) id 1TCbSz-0007CJ-BI; Fri, 14 Sep 2012 20:22:17 +0100 To: Ben Laurie In-reply-to: References: <50453686.9090100@FreeBSD.org> <20120911082309.GD72584@dragon.NUXI.org> <504F0687.7020309@FreeBSD.org> <201209121628.18088.jhb@freebsd.org> <5050F477.8060409@FreeBSD.org> <20120912213141.GI14077@x96.org> <20120913052431.GA15052@dragon.NUXI.org> From: Mark Murray Date: Fri, 14 Sep 2012 20:22:17 +0100 Message-Id: Cc: Arthur Mesh , Ian Lepore , Doug Barton , freebsd-security@freebsd.org, RW , "Bjoern A. Zeeb" Subject: Re: svn commit: r239569 - head/etc/rc.d X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 14 Sep 2012 19:25:08 -0000 Ben Laurie writes: > > What??! Have you seen how Yarrow does its harvesting?? > > If you XOR into the as-yet-unharvested buffer, then appropriately > aligned repeated input makes the buffer zero. There is an "if" and an "appropriately" in there. The entropy is estimated as Zero anyway, in spite of getting "free" TSC jitter, and if this is an attack, the system is screwed to begin with. M -- Mark R V Murray Cert APS(Open) Dip Phys(Open) BSc Open(Open) BSc(Hons)(Open) Pi: 132511160