[Short entry] Linux lets you decide if you trust the CPU's random number generator
-
Since version 4.19, Linux will allow the user to choose when compiling, whether or not to trust the processor's random number generator. For the common mortal, it may not be a big deal, but for systems focused on security, it is a function that can be useful.
The option itself is not a very relevant news, but the fact that the Linux development team no longer trusts the security of the processors. A few days ago, Torvalds already said that he thought it was unfair that software developers had to solve hardware security flaws. That, along with some other complaints related to security flaws in x86 (and specifically in Intel micros) that have come to light in the last year, give meaning to this new function.
Via Phoronix.
-
@cobito said in [Short post] Linux lets you decide if you trust the CPU's random number generator:
The option itself is not a very relevant news, but the fact that the Linux development team no longer trusts the security of the processors.
Indeed, I agree that the crux is there, and also the solution to the Intel/AMD policy of "support it and don't fix it" in the face of the clamor of users, who are tired of so much nonsense.
I would put a statue of this guy (Torvalds) in a square with his name, seriously.