3 ms·
Radioactive decay is slow, slow, slow. There are much better performing sources of randmness, such as beam splitting. Further, not all noise is RF-based. Therm
by atoponce 10y ago
Radioactive decay is slow, slow, slow. There are much better performing sources of randmness, such as beam splitting.
Further, not all noise is RF-based. Thermal noise, for example, is not influenced by RF intereferrence.
- Animats 10y agoAnything which depends on high amplification of an analog signal has potential interference problems. You need a physical phenomenon which produces discrete events, or good shielding. It's not hard to shield against RF and magnetic interference, but it takes some metal and size, which can be a problem for a USB connector sized device. You also have to filter the power going into the shielded area. It's useful to take the output of the noise generator and run it into a spectrum analyzer while using electric motors and walkie-talkies close to the device. If the noise spectrum change shape when you do that, it's not random.
- PhantomGremlin 10y agoRadioactive decay is slow, slow, slow. Here's a cheap way to generate 800 bits per second from radioactive decay. https://www.fourmilab.ch/hotbits/ https://www.fourmilab.ch/hotbits/ Why aren't 800 honest-to-goodness random bits per second enough for all practical purposes? If you need more than that, you should be playing in the big leagues, where using a little USB fob is not the answer!
- atoponce 10y agoWhy aren't 800 honest-to-goodness random bits per second enough for all practical purposes? For seeding the system CSPRNG, that's fine. For securely destroying data, such as wiping hard drives, or creating underlying noise for encrypted filesystems, 800 Bps is going to take you years to work through a 4 TB hard drive.
- PhantomGremlin 10y ago800 Bps is going to take you years to work through a 4 TB hard drive But you don't need to do that. You simply take 256 bits and use them as an AES key. You then generate a stream of bits and write that to disk. Reading the disk afterward is equivalent to breaking AES. Or take Bernstein's advice and use an even better stream cipher. https://cr.yp.to/streamciphers/why.html https://cr.yp.to/streamciphers/why.html And even if you re-key every 1 GB (just for grins), you're still hardly using any random bits at all. OTOH check out this comment elsewhere in this thread. https://news.ycombinator.com/item?id=11560417 https://news.ycombinator.com/item?id=11560417 IDQuantique sells a product that purportedly generates millions of random bits per second. If I were gambling at a casino, I'd feel more comfortable with that than with randomness from an AES stream. Yeah, I know I'm thinking irrationally. But I'm sure I'm not the only one.
- atoponce 10y agoBut you don't need to do that. You simply take 256 bits and use them as an AES key. You then generate a stream of bits and write that to disk. Reading the disk afterward is equivalent to breaking AES. Completely agreed. I've already mentioned in this post about only using the Linux CSPRNG to seed a userspace CSPRNG, because the Linux CSPRNG is horrendously slow, due to its ad-hoc design. However, if the Linux CSPRNG was AES-128 using the standard CTR_DRBG, with AES-NI, it could go north of 2 GiBps without breaking a sweat, keeping clean random.c code (it already ships aes.h), and it's backtracking resistant. However, if you're going to spend good money for hardware producing random values, at least for me, I'm going to want the best bang for my buck. If you look at https://en.wikipedia.org/wiki/Comparison_of_hardware_random_number_generators https://en.wikipedia.org/wiki/Comparison_of_hardware_random_..., you can spend $35 for the WaywardGeek "Infinite Noise RNG", which outputs 300 Kbps, or spend $24 for an RTL-SDR dongle and get about 2.8 MiBps. The value of bits per dollar is much higher with the RTL-SDR than the WaywardGeek. This is considerably cheaper than getting a radioactive sample, coupled with a Geiger counter. IDQuantique sells a product that purportedly generates millions of random bits per second. If I were gambling at a casino, I'd feel more comfortable with that than with randomness from an AES stream. Yeah, I know I'm thinking irrationally. Yeah, that is irrational. The problem with most TRNGs is that their output is biased. As a casino operator, I might be interested if the bias benefits my casino, but I would also need to prove to regulators that I'm not cheating the public. Personally, I'd err on the side of caution when it comes to the law. So either I would whiten the output with a cryptographic primitive (John von Neumann debiasing is too costly, losing at least 1/2 the bits), or just write a userspace CSPRNG, and get the throughput you'll need for the demand. I could then constantly rekey/rseed the generator with the TRNG if I was tinfoil-hat-paranoid. In either case, TRNG or CSPRNG, you'll want exceptional throughput for your casino. Which brings us back to another example of which 800 bps just isn't going to cut it. :)