svn commit: r239569 - head/etc/rc.d

Mark Murray markm at FreeBSD.org
Fri Sep 14 19:25:08 UTC 2012


Ben Laurie writes:
> > What??! Have you seen how Yarrow does its harvesting??
> 
> If you XOR into the as-yet-unharvested buffer, then appropriately
> aligned repeated input makes the buffer zero.

There is an "if" and an "appropriately" in there. The entropy is
estimated as Zero anyway, in spite of getting "free" TSC jitter, and if
this is an attack, the system is screwed to begin with.

M
--
Mark R V Murray
Cert APS(Open) Dip Phys(Open) BSc Open(Open) BSc(Hons)(Open)
Pi: 132511160



More information about the freebsd-security mailing list