AFAIK, Havege uses TSC drift as a random source of entropy, but recent CPUs now have an accurate TSC, so havege hasn't been generating random numbers for a while now. This is also an issue in certain virtualized environments.
PolarSSL had to switch away from using Havege as the basis of their RNG because of this issue: http://polarssl.org/trac/wiki/SecurityAdvisory201102
NACK for the MIR.
AFAIK, Havege uses TSC drift as a random source of entropy, but recent CPUs now have an accurate TSC, so havege hasn't been generating random numbers for a while now. This is also an issue in certain virtualized environments.
PolarSSL had to switch away from using Havege as the basis of their RNG because of this issue: polarssl. org/trac/ wiki/SecurityAd visory201102
http://
NACK for the MIR.