atom feed55 messages in org.freebsd.freebsd-currentRe: entropy reseeding is totally broken
FromSent OnAttachments
Андрей ЧерновOct 19, 2000 9:48 pm 
Udo SchweigertOct 19, 2000 10:57 pm 
Андрей ЧерновOct 19, 2000 11:39 pm 
Андрей ЧерновOct 19, 2000 11:51 pm 
Doug BartonOct 20, 2000 1:18 am 
Андрей ЧерновOct 20, 2000 9:27 am 
Андрей ЧерновOct 20, 2000 9:43 am 
Mark MurrayOct 20, 2000 10:06 am 
Андрей ЧерновOct 20, 2000 1:13 pm 
Warner LoshOct 24, 2000 11:15 am 
Terry LambertOct 25, 2000 3:35 am 
Андрей ЧерновOct 25, 2000 3:50 am 
Mark MurrayOct 25, 2000 10:37 am 
Андрей ЧерновOct 25, 2000 11:12 am 
Wesley MorganOct 25, 2000 2:15 pm 
Mark MurrayOct 25, 2000 3:12 pm 
John W. De BoskeyOct 25, 2000 4:20 pm 
Wesley MorganOct 25, 2000 4:50 pm 
Mark MurrayOct 25, 2000 5:01 pm 
Doug BartonOct 25, 2000 9:28 pm 
Ed HallOct 26, 2000 12:30 am 
David O'BrienOct 26, 2000 12:50 am 
Андрей ЧерновOct 26, 2000 1:47 am 
Kris KennawayOct 26, 2000 2:17 am 
Kris KennawayOct 26, 2000 2:21 am 
Андрей ЧерновOct 26, 2000 2:54 am 
Андрей ЧерновOct 26, 2000 3:01 am 
Rod TaylorOct 26, 2000 3:30 am 
Андрей ЧерновOct 26, 2000 3:34 am 
Jordan HubbardOct 26, 2000 5:20 am 
John W. De BoskeyOct 26, 2000 6:24 am 
Matt DillonOct 26, 2000 9:55 am 
Mark MurrayOct 26, 2000 10:06 am 
Mark MurrayOct 26, 2000 10:17 am 
John BaldwinOct 26, 2000 11:06 am 
Андрей ЧерновOct 26, 2000 11:36 am 
Terry LambertOct 26, 2000 12:04 pm 
Mark MurrayOct 26, 2000 12:39 pm 
Doug BartonOct 26, 2000 12:49 pm 
David O'BrienOct 26, 2000 1:26 pm 
Mark MurrayOct 26, 2000 1:29 pm 
Matt DillonOct 26, 2000 1:47 pm 
Mark MurrayOct 26, 2000 2:02 pm 
Ed HallOct 26, 2000 2:03 pm 
Matt DillonOct 26, 2000 2:25 pm 
Doug BartonOct 26, 2000 2:44 pm 
Poul-Henning KampOct 26, 2000 2:51 pm 
Wesley MorganOct 26, 2000 3:07 pm 
David O'BrienOct 26, 2000 3:15 pm 
Poul-Henning KampOct 26, 2000 3:18 pm 
Jim BryantOct 26, 2000 3:29 pm 
Mark MurrayOct 26, 2000 3:56 pm 
Doug BartonOct 26, 2000 9:00 pm 
Terry LambertOct 27, 2000 5:19 pm 
Doug BartonOct 27, 2000 7:18 pm 
Subject:Re: entropy reseeding is totally broken
From:Doug Barton (Dou@gorean.org)
Date:Oct 27, 2000 7:18:34 pm
List:org.freebsd.freebsd-current

Terry Lambert wrote:

This is sweet! Seems it would give us the full benefits of Mark's randomdev, and fit nicely with our normal configuration framework and gives good flexibility.

It also describes just what we have currently, except it misses the advantages of putting the entropy file on the root partition which makes it available immediately, and doesn't have mounting races built in.

What currently exists does not allow a read-only /. Which sucks.

Please keep a couple things in mind. First, there is no one solution that is going to suit everyone. It's exactly because my /var is not on / that I got interested in patching the current implementation of "save some randomness at boot and read it back in at startup" in the first place. I kept read-only and diskless / cases in mind when I tied my idea into the existing ability to specify the file AND used /var as a failsafe.

Second, Mark has always intended and is currently working on ways to make entropy harvesting happen in the boot phase. No one expected, or represented this file-based method as the ultimate solution.

Third, Schneier's paper suggests loading a file of written-out entropy at boot as an additional reseeding source, so we need to work out the store a file across boot in any case. It's entirely possible that this won't work for some edge cases, but harvesting entropy in the boot process will help alleviate that. Finding answers to the current problems will be easier if we keep the goals clear.

Doug

-- "The dead cannot be seduced." - Kai, "Lexx"

Do YOU Yahoo!?

To Unsubscribe: send mail to majo@FreeBSD.org with "unsubscribe freebsd-current" in the body of the message