Re: /dev/random is probably not

From: Glynn Clements (glynn_at_gclements.plus.com)
Date: 07/05/05

  • Next message: Jack Lloyd: "Re: /dev/random is probably not"
    Date: Tue, 5 Jul 2005 15:59:28 +0100
    To: "Zow" Terry Brugger <zow@llnl.gov>
    
    

    "Zow" Terry Brugger wrote:

    > It's been a while since I looked at the /dev/random design on Linux
    > (probably the early 2.4 days), however one thing that was quite
    > clear was that they did not use any network I/O as entropy sources
    > because an attacker, particularly one that already had control of
    > other machines on the same LAN segment, could have a high degree of
    > control over that source.

    They don't need to have any control; simply being able to observe
    network traffic means that it is no longer random (in the sense of
    "unpredictable", which is what counts from a security perspective).

    -- 
    Glynn Clements <glynn@gclements.plus.com>
    

  • Next message: Jack Lloyd: "Re: /dev/random is probably not"

    Relevant Pages

    • Re: strengthening /dev/urandom
      ... >assume are not under attacker control. ... >entropy sources will fall into this category of uncontrollable devices? ... I expect that there will be some that might come under attacker ... one remaining data source is true random, the output of the XOR is true ...
      (sci.crypt)
    • Re: strengthening /dev/urandom
      ... ]>where the attacker can control the entropy sources feeding ... ]One needs to distinguish control of *all* the entropy sources from ... The attacker might be in contact with aliens who can read your mind. ...
      (sci.crypt)
    • Re: strengthening /dev/urandom
      ... >where the attacker can control the entropy sources feeding ... >of his chosing. ... One needs to distinguish control of *all* the entropy sources from ...
      (sci.crypt)

  • Quantcast