On Tuesday 09 May 2006 22:46, Roland Dreier wrote: > Keir> Where should we get our entropy from in a VM environment? > Keir> Leaving the pool empty can cause processes to hang. > > You could have something like a virtual HW RNG driver (with a frontend > and backend), which steals from the dom0 /dev/random pool. They already have a vTPM - iirc TPMs support random numbers so that could be used. But it's probably complicated to use. But if sampling virtual events for randomness is really unsafe (is it really?) then native guests in Xen would also get bad random numbers and this would need to be somehow addressed. I haven't seen real evidence yet why the virtual events should provide less randomness than the hardware. -And