Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
blahrf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
blahrf
12y ago
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2014-2970 - seems to have been assigned April 21 - to something.. Obviously can't be LibreSSL - it didn't exist then.
2.
▲
CVE-2014-2970 from Dan Goodin article?
1 points
by
blahrf
12y ago
|
2 comments
3.
▲
by
blahrf
12y ago
Ahh, not really - while the process thing the author describes is real - what you're saying is that any two processes show the same values, and that isn't the case. the bad guy needs to control one process to read the values in a
4.
▲
by
blahrf
12y ago
Not sure how a library is going to keep a caller from closing a descriptor - I've certainly seen people attempt to close them all in code before a fork, but that's probably pathological. However that doesn't work across a re
5.
▲
by
blahrf
12y ago
Even though it looks like it won't get called, I'm wondering how bad the voodoo is? Anyone looked at what it is spitting into that hash function? How predictable are those clocks as they change between the memory fetches. Will Lin
6.
▲
by
blahrf
12y ago
"If that's the case?" - Didn't you read the code? :) Sounds like you would prefer no stirring of any new entropy after you chroot... Looks to me like they're trying to require that additional entropy be available, a
7.
▲
by
blahrf
12y ago
You can't simply seed it before a chroot. Look at the code. chacha adds entropy periodically and folds it in. You need entropy in the chroot. The author should probably read 10 lines below the same code he posted in the article. While