看板FB_security
標 題Re: Collecting entropy from device_attach() times.
發信站NCTU CS FreeBSD Server (Tue Sep 25 20:22:41 2012)
轉信站ptt!csnews.cs.nctu!news.cs.nctu!FreeBSD.cs.nctu!freebsd.org!owner-free
--wxDdMuZNg1r63Hyj
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Tue, Sep 25, 2012 at 11:28:13AM +0200, Dag-Erling Sm=F8rgrav wrote:
> Ben Laurie <[email protected]> writes:
> > Not that I dislike Pawel's approach, it seems promising, I'm just
> > pointing out the weakness of the analysis.
>=20
> It is also based on fake data.
>=20
> If you give me a couple of days, I'll try to come up with a patch that
> collects and stores attach times during boot so we can gather and
> analyse real data.
Note that this fake data is the hardest to gather entropy from, as it
doesn't interact with any external hardware. I'm all for testing it on
real hardware and I expect to be able to gather even more entropy from
it (so discarding less than top 7 bits). The problem with making
observations during boot takes much, much longer, so it will limit the
number os samples significantly, and as you know the more samples the
better.
--=20
Pawel Jakub Dawidek
http://www.wheelsystems.com
FreeBSD committer
http://www.FreeBSD.org
Am I Evil? Yes, I Am!
http://tupytaj.pl
--wxDdMuZNg1r63Hyj
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (FreeBSD)
iEYEARECAAYFAlBhhfAACgkQForvXbEpPzTp5QCg0TCtOdPOdULwouNp3PWSM3E6
sNEAn3AaLO5ldhGhz4DFe1Gay7WB7TUE
=5q0B
-----END PGP SIGNATURE-----
--wxDdMuZNg1r63Hyj--