oss-sec mailing list archives
Re: can we talk about secure time?
From: Hanno Böck <hanno () hboeck de>
Date: Mon, 22 Dec 2014 07:39:25 +0100
On Sun, 21 Dec 2014 23:30:10 -0700 Kurt Seifried <kseifried () redhat com> wrote:
Having to reconcile multiple logs/events across widely distributed systems, especially in high volume situations, 1-2 seconds is a deal breaker. Or people running SCADA systems for industrial plants. Or people that run financial systems.
I don't think this contradicts my statement that average consumer hw doesn't need the high accuracy of ntp :-)
So it's not an either/or situation (care about security, or have accurate time, sometimes we need both).
Yeah, I totally agree that this would be the desired thing to have. However the facts are that at the moment we don't. And imho for consumer HW the slight inaccuracy of tlsdate doesn't matter, while the insecurity of ntp does (as the very practical hsts attack has shown). I read these days that the Linux foundation is sponsoring some work on NTP. Anyone involved in this and can comment whether secure authentication for NTP is something that's being looked at or if it is only about creating a better implementation of the ntp software? -- Hanno Böck http://hboeck.de/ mail/jabber: hanno () hboeck de GPG: BBB51E42
Attachment:
_bin
Description: OpenPGP digital signature
Current thread:
- Re: can we talk about secure time?, (continued)
- Re: can we talk about secure time? Daniel Kahn Gillmor (Dec 20)
- Re: can we talk about secure time? ncl () cock li (Dec 20)
- Re: can we talk about secure time? Daniel Micay (Dec 20)
- Re: can we talk about secure time? Florian Weimer (Dec 21)
- Re: can we talk about secure time? Daniel Micay (Dec 21)
- Re: can we talk about secure time? Dave Horsfall (Dec 21)
- leap seconds and security [was: Re: can we talk about secure time?] Daniel Kahn Gillmor (Dec 21)
- Re: can we talk about secure time? Florian Weimer (Dec 21)
- Re: can we talk about secure time? Hanno Böck (Dec 21)
- Re: can we talk about secure time? Kurt Seifried (Dec 21)
- Re: can we talk about secure time? Hanno Böck (Dec 21)
- Re: can we talk about secure time? Walter Parker (Dec 21)
- Re: can we talk about secure time? John Haxby (Dec 22)
- Re: can we talk about secure time? Dave Horsfall (Dec 22)
- Re: can we talk about secure time? Richard Johnson (Dec 25)