Re: One real life secure random generator

New Message Reply About this list Date view Thread view Subject view Author view

Adam Shostack (adam@homeport.org)
Thu, 16 Jul 1998 02:46:24 -0400 (EDT)


While you're theoretically correct, Bram, in practice if I have a
shell account on your machine, you're very likely hosed. If you never
have, check out web sites like rootshell.com or insecure.org.
Everything you need to become a security consultant. :)

Adam

bram wrote:
| On Wed, 15 Jul 1998, Bill Frantz wrote:
|
| > Of course, if you assume that your attacker has hacked your machine, you're
| > toast. There is nothing you can do.
|
| Just because someone's hacked some kind of access doesn't mean they have
| root access - if there are system calls for addSeed() and getRandom() it
| would make sense for them to both be available to processes with very low
| access levels. Also, with RNGs specifically, there's the issue of hacking
| the hardware, which is independent of hacking the software.
|
| -Bram
|

-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:20:25 ADT