Zack's Kernel News

Zack's Kernel News

Article from Issue 246/2021
Author(s):

This month in Kernel News: Opening a Random Can of Worms and Out with the Old.

Opening a Random Can of Worms

Torsten Duwe was mad as hell, and he wasn't going to take it anymore! Or at least, he had certain objections to /dev/random, which he felt should be addressed. In particular, one of the main points of random numbers in the Linux kernel is to support system security. Torsten pointed out that "Input entropy amounts are guesstimated in advance, obviously much too conservatively, compiled in and never checked thereafter; the whitening is done using some home-grown hash function derivative and other non-cryptographic, non-standard operations."

He also remarked with restraint and decorum, that "meanwhile there's quite a maintenance backlog; minor fixes are pending, medium-sized cleanups are ignored and major patch sets to add the missing features are not even discussed."

Torsten said he was in favor of bringing the Linux kernel up to some sort of standards compliance with regards to random numbers, preferably obtaining official certification from one of the organizations that did that sort of thing. But he said he'd settle for /dev/random simply being a reliable source of entropy, even without any certification.

[...]

Use Express-Checkout link below to read the full article (PDF).

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • Kernel News

    Chronicler Zack Brown reports on the latest news, views, dilemmas, and developments within the Linux kernel community.

  • Kernel News

    Chronicler Zack Brown reports on the latest news, views, dilemmas, and developments within the Linux kernel community.

  • Kernel News

    This month we discuss replacing the random number generator, checking when a process dumps core, fixing filesystem security issues, and adding build dependencies to clean the source tree.

  • Kernel News

    Zack Brown reports on: Trusted Computing and Linux; Load Balancer Improvements; and New Random Number Handling.

  • Linus Says No Backdoor in Linux

    Brief dust-up in the kernel community leads to an illuminating look at random number generation.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More

News