Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 30 Nov 1999 10:52:41 -0500
From:      Dan Moschuk <dan@FreeBSD.ORG>
To:        Brad Knowles <blk@skynet.be>
Cc:        Kris Kennaway <kris@hub.freebsd.org>, Dan Moschuk <dan@FreeBSD.ORG>, Bruce Evans <bde@zeta.org.au>, Mike Smith <msmith@FreeBSD.ORG>, audit@FreeBSD.ORG, Warner Losh <imp@village.org>
Subject:   Re: cvs commit: src/sys/i386/conf files.i386 src/sys/kern kern_fork.c   src/sys/libkern arc4random.c src/sys/sys libkern.h
Message-ID:  <19991130105241.A279@spirit.jaded.net>
In-Reply-To: <v04205504b46953e472c1@[195.238.21.204]>; from blk@skynet.be on Tue, Nov 30, 1999 at 11:16:29AM %2B0100
References:  <Pine.BSF.4.21.9911291427180.19254-100000@hub.freebsd.org> <v04205504b46953e472c1@[195.238.21.204]>

next in thread | previous in thread | raw e-mail | index | archive | help

| > If we were to use Yarrow, we get the review for free by virtue of it being
| > designed & reviewed by a professional cryptographer.
| 
| 	Regardless of who the designer was, I think we need a review by 
| an independent third party.
| 
| 	The fact that Yarrow is a respected professional cryptographer 
| would raise the bar and should make it less likely that there are 
| really glaring stupid problems, and might require that we find 
| someone of higher caliber than perhaps we might otherwise have sought 
| out.
| 
| 	But I don't think this eliminates the need for a review by an 
| independent third party.

Right, but I think you miss the point.  Yarrow WILL be reviewed by third
parties whether it is in our kernel or not.

-- 
Dan Moschuk (TFreak!dan@freebsd.org)
"Cure for global warming: One giant heatsink and dual fans!"


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-audit" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?19991130105241.A279>