Re: Why does reading from /dev/urandom deplete entropy so much?



Matt Mackall wrote:
On Tue, Dec 04, 2007 at 04:23:12PM -0600, Mike McGrath wrote:
Matt Mackall wrote:
On Tue, Dec 04, 2007 at 03:18:27PM -0600, Mike McGrath wrote:
Matt Mackall wrote:
which would have been in v2.6.22-rc4 through the normal CVE process.
The only other bits in there are wall time and utsname, so systems
with no CMOS clock would behave repeatably. Can we find out what
kernels are affected?


We can but it will likely take a few weeks to get a good sampling. UUID is unique in the db so when someone checks in with the same UUID, the old one gets overwritten.
We can probably assume that for whatever reason the two things with
duplicate UUID had the same seed. If not, we've got -much- bigger
problems.
Ok, I think I see whats going on here. I have some further investigation to do but it seems that the way our Live CD installer works is causing these issues. I'm going to try to grab some live CD's and hardware to confirm but at this point it seems thats whats going on.

Alright, keep me posted. We probably need a scheme to make the initial
seed more robust regardless of what you find out

Ok, whats going on here is an issue with how the smolt RPM installs the UUID and how Fedora's Live CD does an install. It's a complete false alarm on the kernel side, sorry for the confusion.

-Mike

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



Relevant Pages

  • Re: Fedora 9 and Security
    ... defaults the installer uses have changed, and it makes no sense for the ... installer to ask new users questions like ... "Use UUID, LABEL or device name ?" ...
    (Fedora)
  • Re: Fedora 9 and Security
    ... defaults the installer uses have changed, and it makes no sense for the ... installer to ask new users questions like ... "Use UUID, LABEL or device name ?" ...
    (Fedora)
  • Re: Weirdness with Fedora/XP upgrade
    ... either, please stick to Fedora 8 for the time being, thank you. ... The message cites a long string of gibberish, ... Then it gives no other choice but to exit the installer. ... For the installer, uuid is ...
    (Fedora)
  • Re: Error: no proposal
    ... > Whats wrong??? ... until the installer complains about CD1 not being in. ... The ide-scsi module would appear to bypass whatever problem the normal ... ide-cd driver has with the model of drive I was using (and presumably ...
    (alt.os.linux.suse)
  • Re: Fedora 9 and Security
    ... the installer to ask new users questions like ... LABEL or device name ?" ... I guess my first question would be "If you do not know enough about UUID and partition labels to figure out how to do it, then why are you trying to make the change?" ...
    (Fedora)