4 ms·
What is the possibility that this is an attack on cryptography; convince people that it's safe to produce random numbers this way using an inaccurate "proof" an
by dave2000 10y ago
What is the possibility that this is an attack on cryptography; convince people that it's safe to produce random numbers this way using an inaccurate "proof" and then have an easy/easier time decrypting stuff produced by anyone who uses it?
- swordswinger12 10y agoExactly zero. The authors are well-known theory researchers at a major university, not NSA double-agents. Also, this paper was peer-reviewed and published at one of the top theory conferences in the field. This doesn't guarantee the proof is correct, but it means it received a certain level of scrutiny during the review process. Also also, this paper being public (and high-profile) means that the probability of some mythical 'bug' in the proof remaining undiscovered for long enough for the technique to be applied to real systems is exactly zero.
- erikb 10y ago> Exactly zero. The authors are well-known theory researchers at a major university, not NSA double-agents. Two people said it, so it's about 50-50 at this point. Why would the NSA not pay well-known researchers? Or why do you think they can't afford two experts? The more people agree on it the more likely it is that it is true. And that is not just the case in NSA times. Human error and other tricksters may also be considered.
- dave2000 10y ago"The authors are well-known theory researchers at a major university, not NSA double-agents." I don't understand. Isn't this like the family of someone accused of spying saying "he's not a spy, he's a teacher"?
- swordswinger12 10y agoDave Zuckerman has been doing theoretical CS research for about twenty-five years. Are you saying you think it's likely that either (a) he was an NSA double agent this whole time, or (b) he recently started doing clandestine work for the NSA inserting backdoors into abstract theoretical results about Ramsey graphs and two-source extractors?
- dave2000 10y agoI'm not saying anything about this particular person; just amused as to people's attitudes towards people who might be engaged in secret work on behalf of a government, as if detecting such a person is straightforward, or that people have "spy" on their passport, etc. If you look at the history of spying, leakers and double agents you can see people do it for all sorts of reasons; money, blackmail, belief that your country is doing something wrong or that you need to help your country defeat another country's ideology etc.
- mywittyname 10y agoI think the general consensus is that it doesn't matter whether or not he is some clandestine NSA agent because his paper is just a theoretical proof that is almost entirely removed from any implementations based on his work. If there is some fundamental flaw in his work, then it's likely to be discovered before RNGs based on this work come into wide-spread use. It would be much easier to just code a flaw into the actual implementations of RNGs based on this.
- Natanael_L 10y agoWait for it to be confirmed by other cryptographers before implementing it.
- tptacek 10y agoDon't implement this at all. Even if it's better than the LRNG or FreeBSD kernel RNG, it's not worth pursuing. It's probably an interesting and important CS result. That doesn't mean it belongs in systems.
- Natanael_L 10y agoMy first thought was to make a tiny cheap RNG chip using ~4 different really cheap TRNG sources (diodes, etc) with this as a mixer, for embedded systems (routers and similar). It doesn't matter if a few turn out unreliable, predictable or if they malfunction, you just need those first few hundred bits to seed your system CSPRNG with.
- tptacek 10y agoThere are two real-world problems hardware RNGs can solve, as far as I can tell: 1. They can give userland programs direct access to a permanently "seeded" source of entropy, so that you don't have to route requests through the kernel. 2. They solve the cold-start entropy problem for embedded systems that can't easily generate sufficient entropy within milliseconds of initialization. The former problem is only solved if the HWRNG is part of the ISA for the platform. If you have to pull it from a device, you might as well just pull it from urandom or getrandom(). Other than that, we're not really dealing with problems real security software has. People don't break cryptosystems by attacking the quality of entropy extraction from interrupts and whatnot. I have the same reaction to proposals on LKML about improving the entropy inputs to the LRNG. I mean, great, knock yourself out. But that's not solving a problem systems programmers actually have.