On Fri, May 16, 2008 at 12:19:49PM +0200, Andi Kleen wrote:If programs just need some random data without relying on the fact that it's cryptographically strong /dev/urandom is the right choice. But some programs need entropy for doing crypto stuff, and a local DoS is harmless compared to the consequences of bad /dev/random data. Consider as a worst case the just discovered OpenSSL bug in Debian where all accounts with public key authentification and keys created on a Debian/Ubuntu system during the last 20 months [1] can be taken over by an attacker within less than 20 minutes with a simple brute force attack. [2] cu Adrian [1] 13 months for Debian stable users [2] http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2008-05/msg00416.html -- "Is there not promise of rain?" Ling Tan asked suddenly out of the darkness. There had been need of rain for many days. "Only a promise," Lao Er said. Pearl S. Buck - Dragon Seed -- To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Ingo Molnar | Re: [RFT] x86 acpi: normalize segment descriptor register on resume |
| Andrew Morton | -mm merge plans for 2.6.23 |
| Greg Kroah-Hartman | [PATCH 004/196] Chinese: add translation of SubmittingPatches |
git: | |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| David Miller | Re: [GIT]: Networking |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Ingo Molnar | [bug] stuck localhost TCP connections, v2.6.26-rc3+ |
