3 ms·
I strongly suspect that this information is already included in the Linux kernel RNG, but it is not given much weight in the entropy calculation, on the basis t
by Hello71 7y ago
I strongly suspect that this information is already included in the Linux kernel RNG, but it is not given much weight in the entropy calculation, on the basis that virtualized systems frequently have duplicated MAC addresses (as is allowed on a non-public system), and sometimes also have low initial timestamp resolution.
- throw0101a 7y agoIf a system will be communicating with other systems, it will need a unique Layer 2 address. This can be leveraged for some entropy (certainly you don't have to credit the full 48 bits, but are you tell saying that not even 1-2 bits of credit cannot be applied?). If the system is not communicating with other systems... what attack tree are you actually worried about if it is inaccessible? I would also be curious to know which virtualization environments generate duplicate MAC addresses over (say) dozens of systems?
- Hello71 7y agoMAC addresses are not used in a purely routed/virtualized network. qemu uses the same MAC address by default.