Re: x86 CPU RNG support, take 2

Gabriel Rosenkoetter <[email protected]> Mon, 4 Jan 2016 13:46:40 -0500
Newsgroups gmane.os.netbsd.devel.kernel,gmane.os.netbsd.devel.security,gmane.os.netbsd.devel.crypto
Message-ID <[email protected]>
On 02 Jan, 2016, at 12:01 EST, Taylor R Campbell <[email protected]> wrote:
>   Date: Fri, 1 Jan 2016 14:37:53 -0500
>   From: Thor Lancelot Simon <[email protected]>
>   If I do that, we'll get a cpurng entropy source even on CPUs that don't
>   actually have one.  I'd rather not.
> 
> In that case, why not make cpu_rng_init tell the caller whether or not
> there is a CPU RNG?  It seems to me the CPU feature bits should
> determine the presence of the rndsource, not the dynamic behaviour of
> the hardware itself.

I can't pretend to have been following this terribly close, but isn't "a CPU that claims to have a cpurng entropy source but is lying" kind of a threat model here? (Ala Juniper's recent hoopla.)

--
Gabriel Rosenkoetter
[email protected]
signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iF4EAREKAAYFAlaKvhEACgkQK6uOGBNyA6QIugD/Uhh4KOREmnv8nD3HaJz+n5rk
d4bQ7zaaZVOT0iJyrMcBAIUj2TVWRRyDPHALm+n7INleHiLz89ZC3mCWuWmmFBL+
=tA5K
-----END PGP SIGNATURE-----