On Mon, 26 Jul 1999, James A. Donald wrote:

> > Oh dear!  This suggestion worries me.
> > Is it reasonable to expect this arrangement to be secure
> > against e.g. chosen-entropy attacks?
> 
> Yes:  If the attacker knows exactly when the packets arrive (which he
> cannot) this cannot give him any additional knowledge about the state.

The threat model for yarrow and other SRNG's is that the attacker can not
only tell when entropy is coming in, but control it's contents as well.
The idea is to build something which only fails if the attacker both knows
the state of the pool at some point and manages to control all attempted
reseedings.

-Bram

Reply via email to