Page MenuHomeFreeBSD
Feed Advanced Search

Mar 13 2018

badfilemagic_gmail.com removed a watcher for tests: badfilemagic_gmail.com.
Mar 13 2018, 4:23 PM
badfilemagic_gmail.com removed a watcher for security: badfilemagic_gmail.com.
Mar 13 2018, 4:23 PM
badfilemagic_gmail.com removed a watcher for secteam: badfilemagic_gmail.com.
Mar 13 2018, 4:23 PM

Jan 16 2018

badfilemagic_gmail.com added a comment to D13925: random: Add CCP random source.

So, anything >4 bit (50%) would get you past the measurement part of an entropy analysis. Over 6 and IAD may think you did it wrong. These chips are tricky because they whiten. But unless you are using it as a sole source in your system, it isn’t really an issue with the whitening.

Jan 16 2018, 11:54 AM
badfilemagic_gmail.com added a comment to D13925: random: Add CCP random source.

Conrad, thanks for the details. I also looked at the code in the other review and it looks good. I’d expect whitened output from the ctr-aes drbg to measure ~6.5 bits when put through the sp800-90b tool. That’s roughly what you get out of 1000000 samples from RDRND on Intel.

Jan 16 2018, 3:35 AM
badfilemagic_gmail.com added a comment to D13925: random: Add CCP random source.

Sorry, Removed my last comment as I wrote it thinking it we were talking about ppp link compression as an entropy source then saw the link to the AMD generator. I’m happy to help with measurements or anything else I can there as time allows. So, like Gordon I’m interested in seeing an implementation but think this bit adding it to the source list is fine.

Jan 16 2018, 2:33 AM
badfilemagic_gmail.com added a comment to D13925: random: Add CCP random source.
Jan 16 2018, 2:27 AM

Oct 28 2017

badfilemagic_gmail.com added a comment to D12808: Don't set a harvest_mask by default..

I removed my last comment, because reviewing code on cold medicine isn't a good idea. Stevek is right -- When I talked with lattera earlier this morning, I had an "off by one" error. Setting the mask to 1 leaves you with only cached entropy enabled. 0 leaves it unchanged. My bad and sorry for confusion.

Oct 28 2017, 7:12 PM
badfilemagic_gmail.com added a comment to D12808: Don't set a harvest_mask by default..
Oct 28 2017, 6:52 PM

Jun 11 2017

badfilemagic_gmail.com added a watcher for tests: badfilemagic_gmail.com.
Jun 11 2017, 3:32 PM
badfilemagic_gmail.com added a watcher for secteam: badfilemagic_gmail.com.
Jun 11 2017, 3:31 PM
badfilemagic_gmail.com added a watcher for security: badfilemagic_gmail.com.
Jun 11 2017, 3:31 PM