[147964] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cryptography] What's a Plausible Attack On Random Number

daemon@ATHENA.MIT.EDU (Yaron Sheffer)
Sat Nov 2 12:25:10 2013

X-Original-To: cryptography@metzdowd.com
Date: Sat, 02 Nov 2013 12:50:06 +0200
From: Yaron Sheffer <yaronf.ietf@gmail.com>
To: John Denker <jsd@av8n.com>, John Gilmore <gnu@toad.com>, 
	Jerry Leichter <leichter@lrw.com>,
	"cryptography@metzdowd.com List" <cryptography@metzdowd.com>
In-Reply-To: <527412D2.7050707@av8n.com>
Cc: David Mercer <radix42@gmail.com>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

On 2013-11-01 22:45, John Denker wrote:
> On 11/01/2013 04:04 AM, Yaron Sheffer wrote:
>> It sounds like a quick addition to DHCP - an extension that gets you
>> 256 bits from the server, would solve 99% of the problem we have with
>> embedded devices. It will not be sufficient for high-security
>> environments, because an attacker might be listening on the local
>> LAN, but it will provide the entropy we need to initialize SSH, TLS,
>> IPsec. And it is much better than relying on fixed information (MAC
>> address etc.) and a few bits of timing.
>>
>> Looks very much like an "implement it, standardize it and forget it"
>> kind of thing to me.
>
> Alas, that leaves important parts of the problem unsolved.  We
> cannot "forget it" until we solve the whole problem.
>
> For example:  SSH has to cut host keys when it is first used
> (if not before).  This requires a lot of high-quality randomly-
> distributed bits.  There are a gazillion scenarios where this
> has to happen /before/ the first DHCP happens.  For example,
> I might need to "ssh root@localhost" in order to configure DHCP.
>
I'm probably missing something obvious, but why is "ssh localhost" part 
of your standard routine? I've never had to use it, I can always either 
use "sudo" or simply login as root from a console.

Also, desktop distros are often preconfigured with DHCP. For servers, 
even if you don't take your IP from DHCP, you can request other 
parameters (and my hypothetical random extension) with a DHCPINFORM message.

Thanks,
	Yaron
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography

home help back first fref pref prev next nref lref last post