Thread (26 messages) flat view 26 messages, 8 authors, 2016-06-21

Re: [PATCH v5 0/7] /dev/random - a new approach

From: Sandy Harris <hidden>
Date: 2016-06-19 20:47:38
Also in: lkml

On Sun, Jun 19, 2016 at 3:36 PM, Pavel Machek [off-list ref] wrote:
quoted
The following patch set provides a different approach to /dev/random ...
Dunno. It is very similar to existing rng, AFAICT.
I do not think so. A lot of the basic principles are the same of course,
but Stephan is suggesting some real changes. On the other hand, I'm
not sure all of them are good ideas & Ted has already incorporated
some into the driver, so it is debatable how much here is really useful.
And at the very least, constants in existing RNG could be tuned
to provide "entropy at the boot time".
No, this is a rather hard problem & just tweaking definitely will
not solve it. Ted's patches, Stephan's, mine, the grsecurity
stuff and the kernel hardening project all have things that
might help, but as far as I can see there is no complete
in-kernel solution yet.

Closest thing I have seen to a solution are Denker's suggestions at:
http://www.av8n.com/computer/htm/secure-random.htm#sec-boot-image

Those, though, require changes to build & installation methods
& it might be hard to get distros & device vendors to do it.
So IMO this should be re-done as tweaks to existing design, not as
completely new RNG.
I agree, & I think Stephan has already done some of that.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help