看板FB_security
标 题Re: Collecting entropy from device_attach() times.
发信站NCTU CS FreeBSD Server (Thu Sep 20 20:30:27 2012)
转信站ptt!csnews.cs.nctu!news.cs.nctu!.cs.nctucs.nctu!.org!ownorg!owner-free
Jonathan Anderson <
[email protected]> writes:
> For instance: on an embedded board with few devices, that uses FDT
> rather than bus enumeration whatsits, perhaps the time is more
> deterministic and therefore yields less entropy.
The idea is that attach() initializes the hardware, which is where the
unpredictability comes from. Yes, embedded devices will certainly have
less of it, but they will still have *some*. And yes, we need data,
which is why when I proposed this last week I also proposed a scheme to
record what we feed into Yarrow pre-boot so we could inspect it and
compare it across multiple boots.
DES
--=20
Dag-Erling Sm=C3=B8rgrav -
[email protected]
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"