[offtopic] Re: monitoring entropy

linux kernel account (linker@nightshade.z.ml.org)
Wed, 15 Oct 1997 01:07:05 -0400 (EDT)


On Tue, 14 Oct 1997, Jeffrey B. Siegal wrote:

> While we're on the topic of /dev/random, shouldn't the saved state file be
> readable only by root (to prevent knowledge of the starting state stored in
> the file combined with knowledge of the startup sequence from yielding
> information about the resulting state of the randomizer)? There is no
> mention of this in the comments in random.c, and RedHat release 4.2 (based on
> 2.0.30) leaves the file readable by all.

This is now diverging into userspace concerns.. But anuwhoo, you are
correct.. I doubt this could ever turn into a useful attack.. But just to
correctness sake..