Re: x86 CPU RNG support, take 2
Gabriel Rosenkoetter <[email protected]> Mon, 4 Jan 2016 13:46:40 -0500
| Newsgroups | gmane.os.netbsd.devel.kernel,gmane.os.netbsd.devel.security,gmane.os.netbsd.devel.crypto |
|---|---|
| Message-ID | <[email protected]> |
On 02 Jan, 2016, at 12:01 EST, Taylor R Campbell <[email protected]> wrote: > Date: Fri, 1 Jan 2016 14:37:53 -0500 > From: Thor Lancelot Simon <[email protected]> > If I do that, we'll get a cpurng entropy source even on CPUs that don't > actually have one. I'd rather not. > > In that case, why not make cpu_rng_init tell the caller whether or not > there is a CPU RNG? It seems to me the CPU feature bits should > determine the presence of the rndsource, not the dynamic behaviour of > the hardware itself. I can't pretend to have been following this terribly close, but isn't "a CPU that claims to have a cpurng entropy source but is lying" kind of a threat model here? (Ala Juniper's recent hoopla.) -- Gabriel Rosenkoetter [email protected]
signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iF4EAREKAAYFAlaKvhEACgkQK6uOGBNyA6QIugD/Uhh4KOREmnv8nD3HaJz+n5rk d4bQ7zaaZVOT0iJyrMcBAIUj2TVWRRyDPHALm+n7INleHiLz89ZC3mCWuWmmFBL+ =tA5K -----END PGP SIGNATURE-----