From: "Theodore Y. Ts'o" <tytso@MIT.EDU>
To: Jamie Lokier <lk@tantalophile.demon.co.uk>
Cc: David Schwartz <davids@webmaster.com>,
Karel Kulhavy <clock@atrey.karlin.mff.cuni.cz>,
linux-kernel@vger.kernel.org
Subject: Re: /dev/random: really secure?
Date: Mon, 18 Dec 2000 16:33:13 -0500 [thread overview]
Message-ID: <200012182133.QAA02136@tsx-prime.MIT.EDU> (raw)
In-Reply-To: Jamie Lokier's message of Mon, 18 Dec 2000 21:38:01 +0100, <20001218213801.A19903@pcep-jamie.cern.ch>
Date: Mon, 18 Dec 2000 21:38:01 +0100
From: Jamie Lokier <lk@tantalophile.demon.co.uk>
David Schwartz wrote:
> The code does its best to estimate how much actual entropy it is gathering.
A potential weakness. The entropy estimator can be manipulated by
feeding data which looks random to the estimator, but which is in fact
not random at all.
Yes, absolutely. That's why you have to be careful before you make
changes to the kernel code to feed additional data to the estimator.
*Usually* relying on interrupt timing is safe, but not always. For
example, an adversary can observe, and in some cases control the
arrivial of network packets which control the network card's interrupt
timings. Is it enough to be able to predict with cpu-counter
resolution the inputs to the /dev/random pool? Maybe; it depends on how
paranoid you are.
Note that writing to /dev/random does *not* update the entropy estimate,
for this very reason. The assumption is that inputs to the entropy
estimator have to be trusted, and since /dev/random is typically
world-writeable, it is not so trusted.
- Ted
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/
next prev parent reply other threads:[~2000-12-18 22:04 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2000-12-17 21:50 Karel Kulhavy
2000-12-18 0:18 ` David Schwartz
2000-12-18 8:21 ` Karel Kulhavy
2000-12-18 20:38 ` Jamie Lokier
2000-12-18 21:33 ` Theodore Y. Ts'o [this message]
2000-12-18 22:15 ` Andreas Dilger
2000-12-19 9:27 ` Daniel Stone
2000-12-19 11:49 ` Kurt Garloff
2000-12-19 12:48 ` Peter Samuelson
2000-12-19 16:51 ` Theodore Y. Ts'o
2000-12-19 17:39 ` Pavel Machek
2000-12-18 21:58 ` David Schwartz
2000-12-18 8:49 ` David Feuer
2000-12-18 9:22 ` Martin Mares
2000-12-19 6:49 ` Philipp Rumpf
2000-12-20 3:41 Bernd Eckenfels
2000-12-20 17:58 ` Jamie Lokier
2000-12-20 3:49 Bernd Eckenfels
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200012182133.QAA02136@tsx-prime.MIT.EDU \
--to=tytso@mit.edu \
--cc=clock@atrey.karlin.mff.cuni.cz \
--cc=davids@webmaster.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lk@tantalophile.demon.co.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®