From owner-freebsd-security@FreeBSD.ORG Thu Sep 20 08:58:36 2012 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E4810106566C; Thu, 20 Sep 2012 08:58:36 +0000 (UTC) (envelope-from benlaurie@gmail.com) Received: from mail-vb0-f54.google.com (mail-vb0-f54.google.com [209.85.212.54]) by mx1.freebsd.org (Postfix) with ESMTP id 70FCA8FC0C; Thu, 20 Sep 2012 08:58:36 +0000 (UTC) Received: by vbmv11 with SMTP id v11so2867216vbm.13 for ; Thu, 20 Sep 2012 01:58:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=utHnS4xJifPaj+IFhjeaHwmBiKEGzBTHg4AM7HdxDqc=; b=yBBpJYq2Wod9vXw/NHcmN39B9Oyv58H2lbmYBVs218W/m2R6uXuOB98mmM1/T1gSLh TZLkbbsLy6kffdvxU1UWHbSDQl+/EBIU79ymUpOY45laVLnJE/BxXD/Nvwt3jgkfUotQ nPvYLAB6ULFrFSljL+pdw2Qq6FFr7BKV9v9+s4prv4mTX5mTHevlvZsd03kVAPwegOQG /tHDJu51NLcOY26WZslOVlNYMDE5i4e7+lGX/clqGjOOYRQDPGYHzbcjNpaumY9YOkMT 8yKe+yP60ZziVbR/oHMA6tWMdyTa7/o24M6Dq3uaSC92qtfBpVymb+RD1MM6ByAhZuxM klFg== MIME-Version: 1.0 Received: by 10.58.95.65 with SMTP id di1mr664978veb.55.1348131515814; Thu, 20 Sep 2012 01:58:35 -0700 (PDT) Sender: benlaurie@gmail.com Received: by 10.58.79.243 with HTTP; Thu, 20 Sep 2012 01:58:35 -0700 (PDT) In-Reply-To: <5C632384458A495ABD1EDF8A9A55A3E1@FreeBSD.org> References: <20120918211422.GA1400@garage.freebsd.pl> <5C632384458A495ABD1EDF8A9A55A3E1@FreeBSD.org> Date: Thu, 20 Sep 2012 09:58:35 +0100 X-Google-Sender-Auth: QwSrYHGkEauCDZ_hce3XQ2T34N4 Message-ID: From: Ben Laurie To: Jonathan Anderson Content-Type: text/plain; charset=ISO-8859-1 Cc: freebsd-security@freebsd.org, Pawel Jakub Dawidek Subject: Re: Collecting entropy from device_attach() times. X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 20 Sep 2012 08:58:37 -0000 On Thu, Sep 20, 2012 at 7:54 AM, Jonathan Anderson wrote: > On Wednesday, 19 September 2012 at 20:47, Ben Laurie wrote: > > Erring on the side of underestimation is wise here. > > I agree wholeheartedly, but underestimation means "calculating the correct > value and then applying a safety factor" rather than "picking an arbitrary > number and hoping it's low enough". Ideally, sure.