Subject: Re: rpc xid randomness
To: Jun-ichiro itojun Hagino <itojun@itojun.org>
From: Jaromir Dolecek <jdolecek@NetBSD.org>
List: tech-security
Date: 09/06/2003 22:07:08
Jun-ichiro itojun Hagino wrote:
> 	given horsepower of today's machine the computation overhead is
> 	smaller than the benefit we'll get. (well, some of you run pdp10,
> 	but don't you want your pdp10 be secure against id predictability
> 	attacks?)

Perhaps good analogy might be - would you randomize phone
number allocation?

I don't think randomizing XIDs (or PIDs, for that matter)
is worth the waste^W CPU cycles.

Jaromir
-- 
Jaromir Dolecek <jdolecek@NetBSD.org>            http://www.NetBSD.cz/
-=- We should be mindful of the potential goal, but as the tantric    -=-
-=- Buddhist masters say, ``You may notice during meditation that you -=-
-=- sometimes levitate or glow.   Do not let this distract you.''     -=-