From: linux@horizon.com
To: jlcooke@certainkey.com
Cc: cryptoapi@lists.logix.cz, jmorris@redhat.com,
linux-kernel@vger.kernel.org, tytso@mit.edu
Subject: Re: [PROPOSAL/PATCH] Fortuna PRNG in /dev/random
Date: 24 Sep 2004 06:19:39 -0000 [thread overview]
Message-ID: <20040924061939.5367.qmail@science.horizon.com> (raw)
In-Reply-To: <20040924023413.GH28317@certainkey.com>
BTW, you write:
> It is regarded in crypto circles as the current state-of-the-art
> in cryptographically secure PRNGs.
The question this brings to mind is:
It is? Can you point me to a single third-party paper on the subject?
There's nothing in the IACR preprint archive. Nor citeseer,
The big difference between when /dev/random was designed and today:
- USB is a broadcast bus, and a lot (timing, at least) can be sniffed
by a small dongle. Wireless keyboards and mice are popular. That
sort of user data probably shouldn't be trusted any more. (No harm
mixing it in, just in case it is good, but accord it zero weight.)
- Clock speeds are a *lot* higher (> 1 GHz) and the timestamp counter is
almost universally available. Even an attacker with multiple antennas
pointed at the computer is going to have a hard time figuring out on which
tick of the clock an interrupt arrived even if they can see it.
Thus, the least-significant bits of the TSC are useful entropy on *every*
interrupt, timer included.
For a fun exercise, install a kernel hack to capture the TSC on every
timer interrupt. Run it for a while on an idle system (processor in the
halt state, waiting for interrupts on a cycle-by-cycle basis).
Take the resultant points, subtract the best-fit line, and throw out any
outliers caused by delayed interrupts.
Now do some statistical analysis of the residue. How much entropy do
you have from the timer interrupt? Does it look random? How many lsbits
can you take and still pass Marsaglia's DIEHARD suite? Do any patterns
show up in an FFT?
next prev parent reply other threads:[~2004-09-24 6:23 UTC|newest]
Thread overview: 48+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-09-24 0:59 linux
2004-09-24 2:34 ` Jean-Luc Cooke
2004-09-24 6:19 ` linux [this message]
2004-09-24 21:42 ` linux
2004-09-25 14:54 ` Jean-Luc Cooke
2004-09-25 18:43 ` Theodore Ts'o
2004-09-26 1:42 ` Jean-Luc Cooke
2004-09-26 5:23 ` Theodore Ts'o
2004-09-27 0:50 ` linux
2004-09-27 13:07 ` Jean-Luc Cooke
2004-09-27 14:23 ` Theodore Ts'o
2004-09-27 14:42 ` Jean-Luc Cooke
2004-09-26 6:46 ` linux
2004-09-26 16:32 ` Jean-Luc Cooke
2004-09-26 2:31 ` linux
2004-09-29 17:10 ` [PROPOSAL/PATCH 2] " Jean-Luc Cooke
2004-09-29 19:31 ` Theodore Ts'o
2004-09-29 20:27 ` Jean-Luc Cooke
2004-09-29 21:40 ` Theodore Ts'o
2004-09-29 21:53 ` Theodore Ts'o
2004-09-29 23:24 ` Jean-Luc Cooke
2004-09-30 0:21 ` Jean-Luc Cooke
2004-09-30 4:23 ` Jean-Luc Cooke
2004-09-30 6:50 ` James Morris
2004-09-30 9:03 ` Felipe Alfaro Solana
2004-09-30 13:36 ` Jean-Luc Cooke
2004-10-01 12:56 ` Jean-Luc Cooke
2004-09-30 10:46 ` Jan-Benedict Glaw
-- strict thread matches above, loose matches on Subject: below --
2004-09-27 18:53 [PROPOSAL/PATCH] " Manfred Spraul
2004-09-27 19:45 ` Jean-Luc Cooke
2004-09-28 0:07 ` Theodore Ts'o
2004-09-28 2:24 ` Jean-Luc Cooke
2004-09-28 13:46 ` Herbert Poetzl
2004-09-23 23:43 Jean-Luc Cooke
2004-09-24 4:38 ` Theodore Ts'o
2004-09-24 12:54 ` Jean-Luc Cooke
2004-09-24 17:43 ` Theodore Ts'o
2004-09-24 17:59 ` Jean-Luc Cooke
2004-09-24 20:44 ` Scott Robert Ladd
2004-09-24 21:34 ` Theodore Ts'o
2004-09-25 14:51 ` Jean-Luc Cooke
2004-09-24 18:43 ` James Morris
2004-09-24 19:09 ` Matt Mackall
2004-09-24 20:03 ` Lee Revell
2004-09-24 13:44 ` Jean-Luc Cooke
2004-09-27 4:58 ` Theodore Ts'o
[not found] ` <20040927133203.GF28317@certainkey.com>
2004-09-27 14:55 ` Theodore Ts'o
2004-09-27 15:19 ` Jean-Luc Cooke
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040924061939.5367.qmail@science.horizon.com \
--to=linux@horizon.com \
--cc=cryptoapi@lists.logix.cz \
--cc=jlcooke@certainkey.com \
--cc=jmorris@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®