3 ms·
On that note, would it kill the OpenBSD guys to get on the getrandom(2) train? I get it, they're dying on the “arc4random is better” hill (and, yes, I agree), b
by beefhash 7y ago
On that note, would it kill the OpenBSD guys to get on the getrandom(2) train? I get it, they're dying on the “arc4random is better” hill (and, yes, I agree), but they're literally the last people in the way of making getrandom(2) the new default across not only the usual BSDs and illumos, but also glibc/Linux.
- ColanR 7y agoI trust the OpenBSD team to get security right more than I do any other open source group. So no, I don't think a bandwagon argument is going to persuade them.
- clarry 7y agohttps://www.openwall.com/lists/oss-security/2020/01/28/3 https://www.openwall.com/lists/oss-security/2020/01/28/3 https://www.openwall.com/lists/oss-security/2020/02/24/5 https://www.openwall.com/lists/oss-security/2020/02/24/5
- tenebrisalietum 7y agoDoesn't `getrandom(2)` use `RDRAND`? Should hardware RNGs on ME or PSP enabled CPUs be inherently be trusted - I mean don't the BSD folks recommend not enabling hyperthreading due to Spectre, etc.
- tedunangst 7y agoWould it kill glibc to add arc4random?
- beefhash 7y agoNo, it wouldn't, but they've made abundantly clear they're not interested in doing anything reasonable the BSDs propose.
- hannob 7y agoYou think it's reasonable to have a function called arc4random, even though we know arc4 is insecure and creates biased (i.e. not pseudorandom) output, yet as we know that arc4random really is not "random numbers based on (a)rc4", because internally it's using something secure? So you'd have to actually know that this function named after an insecure stream cipher is a secure way to get random numbers?
- kazinator 7y agoI glanced at an online man page for this several minutes ago which informs that though this was originally RC4 based, it now stands for the "a replacement call for random".
- kazinator 7y agoDo you work with embedded systems that use glibc? It's bloated. It's bad enough keeping up with the cruft dreamed up by POSIX; why add BSD functions that nobody uses outside of the BSD microcosm. Glibc is monolithic; functions that nothing in your system uses are still sitting there in the .so image.
- kazinator 7y agoWould it kill the developer to add: #if !HAVE_ARC4RANDOM uint32_t arc4random_uniform(uint32_t upper_bound) { // ... } #endif to their code? :)
- asveikau 7y agoOpenBSD has the getentropy(2) syscall which is pretty much the same. There is no "flags" parameter like in Linux. But the original rationale for having it be a syscall and not a device [not having an extra open(2) call that can fail] is addressed. arc4random_buf(3) etc. also uses getentropy(2).
- beefhash 7y agoFrom a practical standpoint, I agree (I've started abusing getentropy(2) as a more portable replacement), but it violates the use case though: getentropy(2) is only intended to seed userspace RNGs. Breaking the usage scenario means breaking the API contract.