Re: TPMs and random numbers

From: Jeff Garzik
Date: Thu Sep 12 2013 - 19:39:54 EST


On Thu, Sep 12, 2013 at 5:57 PM, JÃrn Engel <joern@xxxxxxxxx> wrote:
> On Wed, 11 September 2013 14:47:04 -0400, David Safford wrote:
>> But I also think that the existing (certified) TPMs are good enough
>> for direct use.

> That is equivalent to trusting the TPM chip not to be malicious. It

Indeed. While it need not be rngd or userland at all, it seems
reasonable to require any hardware RNG to have its data pushed through
AES mix steps (as kernel random does now IIUC).

Jeff
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/