[tor-bugs] #17799 [Tor]: Hash All PRNG output before use

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Dec 16 14:38:29 UTC 2015


#17799: Hash All PRNG output before use
--------------------+------------------------------------
 Reporter:  teor    |          Owner:
     Type:  defect  |         Status:  needs_revision
 Priority:  Medium  |      Milestone:  Tor: 0.2.8.x-final
Component:  Tor     |        Version:  Tor: unspecified
 Severity:  Normal  |     Resolution:
 Keywords:          |  Actual Points:
Parent ID:          |         Points:
  Sponsor:          |
--------------------+------------------------------------

Comment (by nickm):

 I added a whole bunch of fixes and changes in shake_prng, quite likely
 breaking something.

 Benchmark says it's 6.6x faster than openssl's PRNG for short-ish outputs.
 IMO this means there's no need to jump into the wacky world of libottery's
 additional hacks.

 The main change still needed would be getting #17783 merged, and then
 rebasing this and cleanup up the branch.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17799#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list