logoalt Hacker News

niccetoday at 9:39 AM1 replyview on HN

For this particular bug, for that to apply, you need some sort of oracle which tells that you are actually in the same child process that skips re-randomization before you can reduce the entropy. Based on this post, I cannot see that there is stable oracle to tell that?


Replies

staticassertiontoday at 2:52 PM

I'm not making a claim about this bug, I'm saying that oracles and leaks are common and that nginx seems like a good target for them.