[hafqa] [hafqa] [Bug 2770] New: /dev/urandom produces predicatble data just after boot

From: bugzilla-daemon at lists.maemo.org bugzilla-daemon at lists.maemo.org
Date: Sun Jan 13 15:57:54 EET 2008
https://bugs.maemo.org/show_bug.cgi?id=2770

           Summary: /dev/urandom produces predicatble data just after boot
           Product: System software
           Version: unspecified
          Platform: N810
        OS/Version: Linux
            Status: UNCONFIRMED
          Severity: normal
          Priority: Medium
         Component: general
        AssignedTo: carlos at maemo.org
        ReportedBy: mb at bu3sch.de
         QAContact: hafqa at maemo.org


STEPS TO REPRODUCE THE PROBLEM:
Read data from /dev/urandom immediately after boot.

EXPECTED OUTCOME:
/dev/urandom should get seeded by a seed that was saved on shutdown.

ACTUAL OUTCOME:
/dev/urandom is not seeded.

REPRODUCIBILITY:
always

OTHER COMMENTS:
Not seeding the random number generator might result in security holes in
services such as sshd, if it uses it to generate keys.
We should store a seed to disk on device shutdown and upload that seed to the
kernel RNG in early boot.


-- 
Configure bugmail: https://bugs.maemo.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug, or are watching the QA contact.

More information about the hafqa mailing list