![oss-sec logo](/images/oss-sec-logo.png)
oss-sec mailing list archives
Re: can we talk about secure time?
From: Daniel Micay <danielmicay () gmail com>
Date: Sun, 21 Dec 2014 12:50:07 -0500
On 21/12/14 06:31 AM, Florian Weimer wrote:
In contrast, servers with long-running connections and I/O polling loops often do not react gracefully to jumps in time. (I once disconnected a few hundreds, if not thousands of users from an IRC server just by setting its time correctly.) Sure, you can avoid that by using the appropriate kernel clock for timeout handling, but I have the impression that the correct clock changes every couple of years.
I don't think it has ever changed. CLOCK_MONOTONIC won't *ever* jump either forwards or backwards, but is impacted by clock skew. I don't think most use cases actually want CLOCK_MONOTONIC_RAW, especially considering that there's no vdso implementation so it's slow. Of course, there's lots of buggy software which is why we have stuff like ASLR / SSP in the first place. :)
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- can we talk about secure time? Hanno Böck (Dec 20)
- Re: can we talk about secure time? Stuart Henderson (Dec 20)
- Re: can we talk about secure time? Daniel Kahn Gillmor (Dec 20)
- Re: can we talk about secure time? ncl () cock li (Dec 20)
- Re: can we talk about secure time? Daniel Micay (Dec 20)
- Re: can we talk about secure time? Florian Weimer (Dec 21)
- Re: can we talk about secure time? Daniel Micay (Dec 21)
- Re: can we talk about secure time? Dave Horsfall (Dec 21)
- leap seconds and security [was: Re: can we talk about secure time?] Daniel Kahn Gillmor (Dec 21)
- Re: can we talk about secure time? Florian Weimer (Dec 21)
- Re: can we talk about secure time? Hanno Böck (Dec 21)
- Re: can we talk about secure time? Kurt Seifried (Dec 21)
- Re: can we talk about secure time? Hanno Böck (Dec 21)
- Re: can we talk about secure time? Walter Parker (Dec 21)
- Re: can we talk about secure time? John Haxby (Dec 22)
- Re: can we talk about secure time? Dave Horsfall (Dec 22)
- Re: can we talk about secure time? Richard Johnson (Dec 25)
- Re: can we talk about secure time? Stuart Henderson (Dec 20)