Subject: Re: rpc xid randomness
To: Jun-ichiro itojun Hagino <itojun@itojun.org>
From: Frank van der Linden <fvdl@netbsd.org>
List: tech-security
Date: 09/08/2003 23:17:42
On Mon, Sep 08, 2003 at 07:50:58PM +0900, Jun-ichiro itojun Hagino wrote:
> 	to summarize,
> 	- the currently-committed code is not good.  it is not resistant to
> 	  number reuse/duplication.
> 	- sequential number with time.tv_sec initialization is resistant to
> 	  number reuse/duplication, if we don't set date(1).
> 	- niels' generator is resistant to number reuse/duplcation, and probably
> 	  there's no chance for duplication on reboot (due to the use of random
> 	  number as initialization)

I just want to see some kind of benchmark, like lat_rpc from lmbench.
Or maybe just spray(8).

If it doesn't introduce too much overhead, it's fine with me.

- Frank

-- 
Frank van der Linden                                            fvdl@netbsd.org
===============================================================================
NetBSD. Free, Unix-like OS. > 45 different platforms.    http://www.netbsd.org/