Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1757432Ab3IMCOS (ORCPT ); Thu, 12 Sep 2013 22:14:18 -0400 Received: from imap.thunk.org ([74.207.234.97]:59367 "EHLO imap.thunk.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1757045Ab3IMCOP (ORCPT ); Thu, 12 Sep 2013 22:14:15 -0400 Date: Thu, 12 Sep 2013 22:13:49 -0400 From: "Theodore Ts'o" To: =?iso-8859-1?Q?J=F6rn?= Engel Cc: Andy Lutomirski , Jeff Garzik , David Safford , "H. Peter Anvin" , Leonidas Da Silva Barbosa , Ashley Lai , Rajiv Andrade , Marcel Selhorst , Sirrix AG , Linux Kernel Mailing List , Kent Yoder , David Safford , Mimi Zohar , "Johnston, DJ" Subject: Re: TPMs and random numbers Message-ID: <20130913021349.GB9445@thunk.org> Mail-Followup-To: Theodore Ts'o , =?iso-8859-1?Q?J=F6rn?= Engel , Andy Lutomirski , Jeff Garzik , David Safford , "H. Peter Anvin" , Leonidas Da Silva Barbosa , Ashley Lai , Rajiv Andrade , Marcel Selhorst , Sirrix AG , Linux Kernel Mailing List , Kent Yoder , David Safford , Mimi Zohar , "Johnston, DJ" References: <1378920168.26698.64.camel@localhost> <1378925224.26698.90.camel@localhost> <20130912215718.GF3809@logfs.org> <20130912221340.GG3809@logfs.org> <20130912222309.GH3809@logfs.org> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20130912222309.GH3809@logfs.org> User-Agent: Mutt/1.5.21 (2010-09-15) X-SA-Exim-Connect-IP: X-SA-Exim-Mail-From: tytso@thunk.org X-SA-Exim-Scanned: No (on imap.thunk.org); SAEximRunCond expanded to false Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 926 Lines: 23 On Thu, Sep 12, 2013 at 06:23:09PM -0400, J?rn Engel wrote: > It is worse in three ways: > - it costs performance, > - it may create a false sense of safety and > - it actively does harm if we credit it as entropy. > > How much weight you assign to each of those is up to you. So long as > we don't credit any of it as entropy, I am not too adverse to mixing > it in. But I can equally see benefit in burning the bridges. Well, mixing it in and using /dev/[u]random is certainly better than blindly using the output from the RNG from the TPM directly as a key. I'm not sure what you mean by "burning the bridges"; what is the alternative that you are suggesting? - Ted -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/