Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268522

Re: seeding /dev/random from a security key

From Andy Smith <andy@strugglers.net>
Newsgroups linux.debian.user
Subject Re: seeding /dev/random from a security key
Date 2024-03-25 22:30 +0100
Message-ID <Im03f-1F8n-9@gated-at.bofh.it> (permalink)
References <IlZgS-1EC5-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi,

On Mon, Mar 25, 2024 at 09:24:23PM +0100, Björn Persson wrote:
> Does anyone know of another way to obtain random data from devices of
> this kind?

I have some EntropyKeys and some OneRNGs. I have the rngd packaged
in Debian feeding /dev/random from them.

This had an actual noticeable effect in Debian 9 and earlier, but
since the reworking of Linux's random subsystem I cannot demonstrate
any benefit unless I disable all use of the RDRAND CPU instruction.

EntropyKey is a dead product that can no longer be obtained but
OneRNG is still in production. On their mailing list however, there
is a recent discussion about whether there any point. The conclusion
seems to be "not really". Thread starts here:

    http://lists.ourshack.com/pipermail/discuss/2024-March/000797.html

The thread covers how to make rngd feed /dev/random from a OneRNG in
Debian 12, but it is no longer possible to tell if that does
anything useful.

I most likely will not be replacing these devices when they fail.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

seeding /dev/random from a security key Björn Persson <Bjorn@xn--rombobjrn-67a.se> - 2024-03-25 21:40 +0100
  Re: seeding /dev/random from a security key Andy Smith <andy@strugglers.net> - 2024-03-25 22:30 +0100
    Re: seeding /dev/random from a security key eben@gmx.us - 2024-03-25 23:10 +0100
      Re: seeding /dev/random from a security key Greg Wooledge <greg@wooledge.org> - 2024-03-25 23:50 +0100
    Re: seeding /dev/random from a security key Björn Persson <Bjorn@xn--rombobjrn-67a.se> - 2024-03-26 00:20 +0100
  Re: seeding /dev/random from a security key Jeffrey Walton <noloader@gmail.com> - 2024-03-26 01:50 +0100
    Re: seeding /dev/random from a security key Björn Persson <Bjorn@xn--rombobjrn-67a.se> - 2024-03-26 17:00 +0100
      Re: seeding /dev/random from a security key Jeffrey Walton <noloader@gmail.com> - 2024-03-26 18:10 +0100
        Re: seeding /dev/random from a security key Björn Persson <Bjorn@xn--rombobjrn-67a.se> - 2024-03-27 00:20 +0100
          Re: seeding /dev/random from a security key Jeffrey Walton <noloader@gmail.com> - 2024-03-27 00:20 +0100

csiph-web