3 ms·
Here in Ukraine, we have a nice saying: "Don't rush into the hell before your father". I.e. don't make any prejudiced conclusions before you get any single ans
by plugnburn 11y ago
Here in Ukraine, we have a nice saying: "Don't rush into the hell before your father".
I.e. don't make any prejudiced conclusions before you get any single answer.
I am too in a doubt that the OP sees the diference between OTP and SSC, but he has to answer himself.
Cryptography was my primary speciality in the university, and I know for sure that "information-theoretic security", i.e. degree of randomness, of a bit sequence, isn't a rocket science. For it to exist, the sequence must pass a row of tests. It's not so hard to achieve. Finding the actual entropy source is much harder. Without a dedicated chipset (have you ever heard of Gryada-3 (Гряда-3, roughly translated as Ridge-3) RNG module? Probably not, it's a Ukrainian invention), human interaction (mouse movement etc) or using external sensors (temperature deviations, for example) the only entropy source I can think of is RDTSC timestamp gathering.
For us mere mortals, even /dev/random will do. But the most interesting question for me is how the hell (which you shouldn't rush into before your father) the OP is going to distribute and sync the random pile of data. That alone is quite a hard problem, especially if the pile is distributed between more than two users.
So let's be patient and wait for the answers.
- Tomte 11y ago"For it to exist, the sequence must pass a row of tests." Sorry, that's laughable. "even /dev/random will do" It's just not OTP anymore, but who cares?
- arsenide 11y agoWhy is it laughable? I'm not disagreeing with you: I am rather curious.
- Tomte 11y agoBecause information theoretic security is a property of a randomness source, not its output data. And it has a stringent definition. The idea that "I'm throwing the output of some randomness source at Diehard, and if Diehard says it's good then the source provides information theoretically secure random numbers" is a category error at best.
- plugnburn 11y agoCould you provide the stringent definition regarding the randomness source, not a cryptosystem? I see it as this: if the randomness source cannot be one more time put into the same conditions that it would start repeating the same sequence, and its output is random enough (i.e. passes the tests), it may be considered safe for OTP key data production.
- plugnburn 11y agoHave you ever read how /dev/random data are actually gathered and how do they differ from /dev/urandom?
- Tomte 11y agoNice try. ;-) http://www.2uo.de/myths-about-urandom/#computationally-secure http://www.2uo.de/myths-about-urandom/#computationally-secur...
- plugnburn 11y agoIn fact, nothing prevents us to lay a custom layer of gathering the entropy over (u)random, so all the issues mentioned in that article can be easily circumvented. If I had a license and enough money to buy Gryada-3 module, I certainly wouldn't look into any pure-software solutions.