libsodium mess

Eric S. Raymond esr at thyrsus.com
Thu Jan 19 19:30:35 UTC 2017


Gary E. Miller <gem at rellim.com>:
> > - to fuzz the low-order bits of the clock.
> 
> Hmm, can you expand on this a bit?  Which clock?  How much fuzz?
> Does this degrade anything?

Whenever ntpd polls the system clock, it fuzzes the lowest-order digits
of the result. The amount of fuzz to apply is bounded by half the measured
interval between system clock ticks.

That shouldn't degrade anything. I presume it's a measure to foil timing
attacks of some sort.  Daniel might be able to say more.
-- 
		<a href="http://www.catb.org/~esr/">Eric S. Raymond</a>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 811 bytes
Desc: not available
URL: <https://lists.ntpsec.org/pipermail/devel/attachments/20170119/96346562/attachment.bin>


More information about the devel mailing list