From owner-freebsd-security@FreeBSD.ORG Thu Sep 6 22:42:35 2012 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: by hub.freebsd.org (Postfix, from userid 664) id 73482106566C; Thu, 6 Sep 2012 22:42:35 +0000 (UTC) Date: Thu, 6 Sep 2012 15:42:34 -0700 From: David O'Brien To: RW Message-ID: <20120906224234.GA18953@dragon.NUXI.org> References: <5043DBAF.40506@FreeBSD.org> <20120903171538.GM1464@x96.org> <50450F2A.10708@FreeBSD.org> <20120903203505.GN1464@x96.org> <50451D6E.30401@FreeBSD.org> <20120903214638.GO1464@x96.org> <50453686.9090100@FreeBSD.org> <20120904220754.GA3643@server.rulingia.com> <20120906174247.GB13179@dragon.NUXI.org> <20120906230157.5307a21f@gumby.homeunix.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20120906230157.5307a21f@gumby.homeunix.com> X-Operating-System: FreeBSD 10.0-CURRENT X-to-the-FBI-CIA-and-NSA: HI! HOW YA DOIN? can i haz chizburger? User-Agent: Mutt/1.5.20 (2009-06-14) Cc: Arthur Mesh , freebsd-security@freebsd.org, freebsd-rc@freebsd.org, Doug Barton Subject: Re: svn commit: r239569 - head/etc/rc.d X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: obrien@freebsd.org List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 06 Sep 2012 22:42:35 -0000 On Thu, Sep 06, 2012 at 11:01:57PM +0100, RW wrote: > On Thu, 6 Sep 2012 10:42:47 -0700 David O'Brien wrote: > > On Wed, Sep 05, 2012 at 08:07:54AM +1000, Peter Jeremy wrote: > > > >What if, instead of replacing /entropy, we add an additional file > > > >in /var/db/entropy at boot time that is numerically 1 higher than > > > >$entropy_save_num ? > > > That sounds like a reasonable idea. > > > > I don't see what that adds or fixes. It does not correct the > > possible reuse of seed material. > > Reusing a secure entropy file is only a problem if the complete history > of yarrow, from boot until some significant output, is exactly the same > as on a previous boot. I feel this is discussed in the yarrow and Fortuna papers. Please provide specific section reference backing your position for me to read. Why are we trying to invent a new shiny way to address an issue discussed by yarrow's author? What is your specific argument against deleting the consumed seed file? Do you feel the 4k bytes of /entropy is too little? -- -- David (obrien@FreeBSD.org)