[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] PV random device


  • To: Sarah Newman <srn@xxxxxxxxx>
  • From: Andy Smith <andy@xxxxxxxxxxxxxx>
  • Date: Tue, 6 Oct 2015 04:29:07 +0000
  • Cc: xen-devel <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • Delivery-date: Tue, 06 Oct 2015 04:29:28 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xen.org>
  • Openpgp: id=BF15490B; url=http://strugglers.net/~andy/pubkey.asc

Hi Sarah,

On Mon, Oct 05, 2015 at 09:12:47PM -0700, Sarah Newman wrote:
> On 10/05/2015 08:35 PM, Andy Smith wrote:
> > So, I've been keeping (PV) domUs topped up with entropy by giving
> > them access to hardware RNGs (initially Entropy Keys, but since the
> > company making them failed I've switched to OneRNGs).
> 
> This is not a satisfactory solution for us because even if we were
> willing to do USB passthrough, the number of hardware devices
> needed would be expensive and difficult to manage.

I don't find it a problem as:

- Your typical EntropyKey or OneRNG can generate quite a bit of
  entropy. Maybe 32 kilobytes per second for ~$50 each.

- You can access them over the network so no USB passthrough needed.

- Making it opt-in means only people who actually know and care what
  entropy is will use it. :)

So for me it's a somewhat hacky but still scalable solution. My main
concern is that it's going to some length to provide a service that
isn't actually required.

Cheers,
Andy

-- 
> I'd be interested to hear any (even two word) reviews of their sofasâ
Provides seating.
 â Andy Davidson

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.