6 ms·
Perhaps Math.random()@computer1 and Math.random()@computer2
by plainOldText 10y ago
Perhaps Math.random()@computer1 and Math.random()@computer2
- willvarfar 10y agoAs long as you ensure they are different algos and have different seeds...? As I write that I get a funny "no way" feeling. This is so unnatural feeling, if Its true it is indeed a breakthrough. I have to read the paper again. When people complained about Linux mixing in the Intel hardware rng Linus replied that mixing low quality sources have good entropy - and he got a lot of stick for that. That they are on different computers is immaterial.
- mwpmaybe 10y ago> Linus replied that mixing low quality sources have good entropy Hopefully this research yields a wonderful new algorithm for combining the sources and makes it a simple kernel patch away.
- merijnv 10y agoLinus actually argued something slightly different. That discussion was about whether a "bad" random source can weaken a "good" source. This paper is about constructing a "good" source from two independent "bad" sources. The problem with Linux was people complaining that mixing the Intel RNG into the existing entropy pool would lower the entropy of the entire pool, effectively letting a backdoored Intel RNG render the random system untrustworthy. Linus' response was the fairly simple/logical observation that "that's not how entropy works". Suppose we have a random bit string with entropy X and we xor the bit string with a completely deterministic bitstring, what's the result? Clearly you have a bitstring that STILL has entropy X, because the result is completely dependent on our initial bitstring. Mixing with a deterministic bitstring doesn't make the output of our XOR any more predictable then the original bitstring, it's equally random. So Linus' argument was that "IF the Intel RNG is completely backdoored and deterministic mixing it with the entropy pool will have no effect on the entropy in the pool. HOWEVER, if the Intel RNG is anything but completely deterministic, i.e. there is even a tiny bit of randomness in it, this will actually INCREASE the pool's entropy. So mixing a completely backdoored RNG will have no negative impact, but mixing anything that's not 100% predictable will have a positive impact, so there's no reason to not always mix the hardware RNG with the pool.
- Natanael_L 10y agoThat's also assuming it isn't maliciously correlated to produce an output that after XOR leaks secret entropy.
- merijnv 10y agoSure, if you're hardware RNG is inspecting your RAM and trying to compromise your entropy pool that could be done, but: 1 - The entropy mixing is more complex than simply XOR, making such a thing considerably harder 2 - If you expect this level of backdooring from your CPU, you have bigger problems :)
- goldenkey 10y agoSee my post about why multiplying two sources of random numbers will actually reduce the entropy to less than even a single one of the sources: https://news.ycombinator.com/reply?id=11719840&goto=item%3Fid%3D11719543 https://news.ycombinator.com/reply?id=11719840&goto=item%3Fi... It is imperative to use a binary hash that leaves all possible input pairs equally probable for the output. That is what this paper is about.