From owner-freebsd-hackers@freebsd.org Wed Mar 15 13:53:52 2017 Return-Path: Delivered-To: freebsd-hackers@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0F705D0D690 for ; Wed, 15 Mar 2017 13:53:52 +0000 (UTC) (envelope-from crest@rlwinm.de) Received: from smtp.rlwinm.de (smtp.rlwinm.de [IPv6:2a01:4f8:201:31ef::e]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id C64D915A4 for ; Wed, 15 Mar 2017 13:53:51 +0000 (UTC) (envelope-from crest@rlwinm.de) Received: from crest.lan.bultmann.eu (unknown [87.253.189.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.rlwinm.de (Postfix) with ESMTPSA id AD74B7900 for ; Wed, 15 Mar 2017 14:53:46 +0100 (CET) Subject: Re: arc4random weakness To: freebsd-hackers@freebsd.org References: <20170313220639.GB65190@pyro.eu.org> <20170315130615.GC25448@pyro.eu.org> From: Jan Bramkamp Message-ID: <76e73904-82be-ed19-5757-ab58615ffb44@rlwinm.de> Date: Wed, 15 Mar 2017 14:53:45 +0100 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:45.0) Gecko/20100101 Thunderbird/45.8.0 MIME-Version: 1.0 In-Reply-To: <20170315130615.GC25448@pyro.eu.org> Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Mar 2017 13:53:52 -0000 On 15/03/2017 14:06, Steven Chamberlain wrote: > Steven Chamberlain wrote: >> Please consider switching to ChaCha20 in the long term (kern/182610), >> but right now, at least increase the amount of early keystream that is >> discarded. > > Many, many thanks delphij+so for applying the latter change so quickly! > > Also it is great to see INHERIT_ZERO was added to mmap(2)! Can we also get MAP_ZERO to deal with truncation of mmap()ed file descriptors?