看板FB_security
标 题Re: svn commit: r239569 - head/etc/rc.d
发信站NCTU CS FreeBSD Server (Sat Sep 15 04:22:17 2012)
转信站ptt!csnews.cs.nctu!news.cs.nctu!.cs.nctucs.nctu!.org!ownorg!owner-free
Ben Laurie writes:
> > What??! Have you seen how Yarrow does its harvesting??
>
> If you XOR into the as-yet-unharvested buffer, then appropriately
> aligned repeated input makes the buffer zero.
There is an "if" and an "appropriately" in there. The entropy is
estimated as Zero anyway, in spite of getting "free" TSC jitter, and if
this is an attack, the system is screwed to begin with.
M
--
Mark R V Murray
Cert APS(Open) Dip Phys(Open) BSc Open(Open) BSc(Hons)(Open)
Pi: 132511160
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"