看板FB_security
标 题Re: Collecting entropy from device_attach() times.
发信站NCTU CS FreeBSD Server (Fri Sep 21 07:01:33 2012)
转信站ptt!csnews.cs.nctu!news.cs.nctu!FreeBSD.cs.nctu!freebsd.org!owner-free
On Thu, 20 Sep 2012 11:05:32 +0200
Dag-Erling Sm=F8rgrav wrote:
> RW <[email protected]> writes:
> > Dag-Erling Sm=F8rgrav <[email protected]> writes:
> > > I would also suggest modifying yarrow to block reseeding as long
> > > as possible, ideally right up until the first time something asks
> > > for a random number, since reseeding throws away all accumulated
> > > entropy.
> > reseeding doesn't throw away entropy
>=20
> Yes, it does.
Would you elaborate? I don't see what you mean by that?
When yarrow reseeds, the previous generator key is hashed with the
pool[s], into the new key. They key will therefore *accumulate* entropy
across multiple reseeds.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"