Ben Laurie writes:
> > What??! Have you seen how Yarrow does its harvesting??
> 
> If you XOR into the as-yet-unharvested buffer, then appropriately
> aligned repeated input makes the buffer zero.

There is an "if" and an "appropriately" in there. The entropy is
estimated as Zero anyway, in spite of getting "free" TSC jitter, and if
this is an attack, the system is screwed to begin with.

M
--
Mark R V Murray
Cert APS(Open) Dip Phys(Open) BSc Open(Open) BSc(Hons)(Open)
Pi: 132511160

_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"

Reply via email to