4 ms·
There is a fix and it is not crazy. The gist is they were able to brute force the PRNG of the machines and predict their future state. Hardware RNG is thr answe
by bitexploder 10y ago
There is a fix and it is not crazy. The gist is they were able to brute force the PRNG of the machines and predict their future state. Hardware RNG is thr answer. In crypto it is obviously bad if someone can predict anything about your random values (keys / IVs). A hardware RNG, "cryptographically strong" RNG algorithms, and resetting the RNG very often make this problem go away.
- klodolph 10y agoYou might be interested in seeing the legal requirements. Section 1.400: http://gaming.nv.gov/modules/showdocument.aspx?documentid=2919 http://gaming.nv.gov/modules/showdocument.aspx?documentid=29...
- bitexploder 10y agoThat is a surprisingly detailed and reasonable requirement for the most part. Some of those side channel attack resistant requirements are wishful thinking in some ways, but it is also probably obvious in general, if someone is say, performing DPA in the middle of your casino.
- bluGill 10y agoThe problem is that you cannot add a hardware random number generator to existing machines and the cost of buying a new machine is high enough that casinos do not want to do it. If the scammers get too big the casinos will replace the compromised machines and the scam ends. The scammers seem to know this: they are targeting more an more casinos around the world in an apparent effort to make sure it is worth the risk. Actually you don't need hardware random number generators. There is enough variance in human input to feed a cryptograhic random number generator. The code to add this probably wouldn't be that hard to write (they might be 8 bit CPUs or some such limit that makes it impossible though). However all code changes have to be certified by regulatory bodies (for good reason) which makes it not worth the effort to fix old machines.
- bitexploder 10y agoThat is fair enough. For older machines I have no idea what the answer is. I just mean designing this securely is not too hard. Hardware RNG is cheap, though. You are right though, these old machines do present a pickle.
- rimantas 10y agohow about adding some random delay circuit for the spin button? It would mess up with timing and that's enough.
- logfromblammo 10y agoAh, but how would you determine the randomness of the delay?