12 ms·
A wall of lava lamps helps encrypt the internet
- diyseguy 9y agoSGI did it first
- amelius 9y agoSo how many bits does it produce per second per lamp?
- Kequc 9y agoThat's approximately 100 lava lamps each at 100W = 10,000W = 10kW/h * 20.4 cents = $2.04/h * 24 = $48.96/day $1,489.20/month. Ignoring the fact that is very little money in Silicon Valley. Lava lamps consume a large amount of electricity in order to generate the heat they need. There are cheaper better ways to generate randomness, this is purely for spectacle clearly. It makes me nervous more than anything. If that's the front they put up, inside is there a Rube Goldberg machine that triggers DDoS protection?
- pbhjpbhj 9y agoThey should "power" the lamps with excess CPU/processor heat.
- hinkley 9y agoNot too much power though. They can explode.
- ams6110 9y agoIIRC a standard size lava lamp used much less than a 100W bulb. So your costs are maybe half that.
- adzm 9y ago40W on mine fwiw
- hinkley 9y agoAs someone else pointed out, they overheat. So if you want to run them all day you might go down to a 30 or 25 watts. But there are probably a bunch of other Brownian motion machines you could use that take a lot less power. Like those glitter lamps. You’d need a higher res camera.
- JdeBP 9y agoInfinite improbability is just around the corner, eh? (-:
- techman9 9y agoI think the intent is for this to be a functional art installation more than anything. Of course there are less expensive (and more "practical" ways of accumulating entropy), but this is a very cool art project that provides a pretty core function. Yeah, maybe it's kind of expensive to run, but that's not that extreme. A lightbulb is like 100W too right?
- NightlyDev 9y ago100 watt is way too much, 25W/each is a more realistic number.
- bjoli 9y agoIf you want to go with lamps or light as the source of entropy and still have a nice wall to show people, plasma globes are probably a better way of doing it.
- chiph 9y agoIf Cloudflare ever open another office, they could use a wall full of Drinky Birds for randomness. https://en.wikipedia.org/wiki/Drinking_bird https://en.wikipedia.org/wiki/Drinking_bird
- Negative1 9y agoI did something similar a few years back, except instead of Lava lamps, I used a Geiger counter module connected to an Arduino (scrap from a project I was working on to make something economical for civilian use after the Fukushima Daiichi nuclear disaster). Basically, the background radiation is used as the PRNG number (not just as the seed). I found out later that someone at Sparkfun already did this: https://www.sparkfun.com/tutorials/132 https://www.sparkfun.com/tutorials/132
- deleted 9y ago[deleted]
- maxsavin 9y agoBut is it really random? #conspiracy
- cryptoz 9y agoIt's open to the public‽ Seems like a bad idea to let a potential spy in there to set up a camera and de-randomize this source of random info. Also, the headline on HN declares it a fact that the lava lamps are assisting in the encryption, but the article is careful to say "maybe", "might", etc. This seems wildly insecure and much more likely to represent a weak link than to actually aid in randomness.
- ejcx 9y agoEven if the data is not random it doesn't weaken your kernel prng by writing non-random data to urandom. Don't overcomplicate your threat model with non-existent risks
- drewbug 9y agohttps://blog.cr.yp.to/20140205-entropy.html https://blog.cr.yp.to/20140205-entropy.html
- schoen 9y agoDidn't DJB somewhere describe a PRNG model in which this is not true and you shouldn't let an adversary give you PRNG seeds? (I don't have any problem with what CloudFlare is doing.) Edit: While I was writing this comment, drewbug linked to the exact DJB post I was thinking of. Thanks!
- tedunangst 9y agoSomeone observing the lava lamps still can't control their appearance.
- __s 9y agoThe nice thing about randomness is that given a random blob, you can xor a non random blob & it's just as random. So this is one input of entropy amongst a cocktail of sources
- brians 9y ago
- ceph_ 9y agoThere's a good Tom Scott video on this too. Like most of his stuff, it's well worth the watch. https://youtu.be/1cUUfMeOijg https://youtu.be/1cUUfMeOijg
- RKearney 9y agoPrevious discussions: https://news.ycombinator.com/item?id=15048655 https://news.ycombinator.com/item?id=15048655 https://news.ycombinator.com/item?id=15114275 https://news.ycombinator.com/item?id=15114275
- wkandek 9y agoMore details on how it is implemented here: https://blog.cloudflare.com/lavarand-in-production-the-nitty-gritty-technical-details/ https://blog.cloudflare.com/lavarand-in-production-the-nitty...
- jgrahamc 9y agoThe Cloudflare blog posts that go into this in detail: https://blog.cloudflare.com/lavarand-in-production-the-nitty-gritty-technical-details/ https://blog.cloudflare.com/lavarand-in-production-the-nitty... https://blog.cloudflare.com/randomness-101-lavarand-in-production/ https://blog.cloudflare.com/randomness-101-lavarand-in-produ...
- natch 9y agoHow do they prevent the camera or its outgoing feed from being hacked or replaced by the NSA? Edit: I see this is addressed partially by wkandek's link elsewhere in this discussion.
- booleanbetrayal 9y agoHack the Planet = Hack a Camera?
- booleanbetrayal 9y agoAh, apparently, based on one of the detailed links just posted, it just provides one feed of entropy to the mix -- not the sole source.
- samuel 9y agoI might be prejudiced, but this looks like a big PR stunt/done for the cool factor kind of thing. Aren't there simpler/saner alternatives for getting good randomness?
- Houshalter 9y agoWhat would be an easier way? A wall of lava lamps seems pretty easy to set up.
- comboy 9y agobusy streets webcams?
- MBCook 9y agoThat would be susceptible to traffic patterns.
- firethief 9y agoNot meaningfully. The input doesn't need to be uniform, just unpredictable. Statistical patterns are fine, as long as no one can predict exactly what's going to happen (to the pixel level). Even if all the drivers on the road were collaborating, they couldn't coordinate well enough to feed the camera adversarially predictable inputs. At least, not human drivers...
- MBCook 9y agoI was thinking more along the lines of busy/non-busy times may affect how much random data you get at different times of the day/week. Not specifically some sort of giant coordinated attack to modify the randomness generated to specific values.
- comboy 9y agoCars don't look exactly the same and are not in the exact same places. Lighting changes. People look very different and walk different paths. It's going through PRNG so even very small pixel differences (which you can find even on an empty street thanks to changing weather, litter, wind and so on) are good enough if they are unpredictable. In other words, when you compare pictures of the same lava lamp with pictures of some random cars, I think you will be able to find more patterns in the lava lamp movement. You would also likely be able to predict it better (well that's the same thing I guess).
- xir78 9y agoDo they have the distribution posted somewhere?
- sgt101 9y agoThe issue with this is the nature of devices (cameras) and device drivers - which both have non random characteristics.
- xg15 9y agoAssuming this is not a PR stunt: Wouldn't different lighting conditions throughout the day lead to patterns in the randomness?
- GuiA 9y agoSee the blog post. Other sources are used. https://blog.cloudflare.com/lavarand-in-production-the-nitty-gritty-technical-details/ https://blog.cloudflare.com/lavarand-in-production-the-nitty...
- org3432 9y agoWas my thought too, you're introducing a number of unknown variables that could skew the distribution.
- firethief 9y agoAnother pattern is the bases of the lamps rarely change. Patterns are OK; the important thing is that unpredictable components are present.
- olivierva 9y agoA variation on Brownian Motion: https://en.wikipedia.org/wiki/Brownian_motion https://en.wikipedia.org/wiki/Brownian_motion
- oppositelock 9y agoWe did this exact thing at SGI 20 years ago. https://en.wikipedia.org/wiki/Lavarand https://en.wikipedia.org/wiki/Lavarand I wonder if Cloudflare was inspired by that.
- tptacek 9y agoYes, they were; they mentioned it explicitly.
- erric 9y agoThe article doesn’t actually mention SGI.
- Izkata 9y agoThe article explains how it works, without any mention of the inspiration.
- nickpsecurity 9y agoThis is pretty cool use of tech that goes back to SGI. It's definitely not the practical solution to TRNG's. There are analog solutions that use basic physics and EE techniques to generate noise fast, cheap, in tiny footprint if you want, and with a lot of potential diversity in supply chain. Here's an example of an open one: https://github.com/waywardgeek/infnoise/blob/master/README.md https://github.com/waywardgeek/infnoise/blob/master/README.m...
- JoeDaDude 9y agoIf you can't afford that many lava lamps, NIST provides an alternative, free service: https://beacon.nist.gov/home https://beacon.nist.gov/home
- bhhaskin 9y agoWARNING: DO NOT USE BEACON GENERATED VALUES AS SECRET CRYPTOGRAPHIC KEYS. So probably not a good idea.
- foodstances 9y agoUsing the values directly is not the same thing as feeding the values into a RNG.
- kvakil 9y agoNo, the reason you aren't supposed to use it to generate cryptographic keys is because it's public: so it effectively provides no (or nearly no) entropy. It's the same reason you shouldn't use the current time as a seed for a PRNG. NIST Beacon is more intended for things like lottery drawings, where you want to prove that you're generating the random numbers in an unbiased manner.
- dboreham 9y agoFor a few seconds I was thinking...Bacon.
- patcheudor 9y agoMy lesson from my personal experiments with Lavarand: you must have more than one lamp, not necessarily for more entropy, but for fail-over and uptime. At approximately ~30 hours, my vintage 70's lamp 'gives up' - the fluid temperature becomes pretty even between the bottom and the top. It's all essentially superheated as far as the wax is concerned and it simply stays in one place as a dome at the bottom, barely moving. This isn't good for creating random data. By using multiple lamps, it's possible to power cycle them. Ideally, every ten hours or so, remaining off for a couple hours.
- deleted 9y ago[deleted]
- LeoPanthera 9y agoWould attaching a heat sink to the top of the lamp solve that problem? So there's always a heat gradient. It would probably work better in a colder room, too.
- s0rce 9y agoPut a TEC on the top with a heatsink if your room is warm.
- Bromskloss 9y agoWould a heat sink on top help, perhaps?
- minimaxir 9y agoIt's worth nothing that the lava lamps are visible street side through large glass windows, so it serves as an eye-catching artpiece for passerbys.
- jlgaddis 9y agoCloudflare's own blog posts about this: https://blog.cloudflare.com/lavarand-in-production-the-nitty-gritty-technical-details/ https://blog.cloudflare.com/lavarand-in-production-the-nitty... https://blog.cloudflare.com/randomness-101-lavarand-in-production/ https://blog.cloudflare.com/randomness-101-lavarand-in-produ...
- anonu 9y agoSeems like a waste of energy... I can imagine putting a weather station on the roof would be more useful (albeit less cool). Use multiple sensors for rainfall, UV, wind speed, wind direction, temperature, pressure and aggregate the signals from each... Surely the combination of localized weather readings would provide enough randomness.
- lalos 9y agoReminded me about the dice-o-matic https://news.ycombinator.com/item?id=14806986 https://news.ycombinator.com/item?id=14806986
- goblins 9y agoI like this. Seems like a simple analog solution to fairly difficult digital problem; true randomness that is.
- saagarjha 9y ago> Since computer codes are created by machines with relatively predictable patterns, it is entirely possible for hackers to guess their algorithms, posing a security risk. That’s not what “computer codes” and “algorithms” mean.
- tempestn 9y agoCool. Would have been nice if the article at least devoted 1-2 sentences to explaining PRNG seeds though.
- angel_j 9y agoI prefer cosmic background radiation.
- deleted 9y ago[deleted]
- jorgec 9y agoGenerating a random number by using microseconds as a seed is more than enough for practically every single case. It still hasn't been cracked or predicted. Some people say that, in theory, it could be cracked however, i tried and its impossible, modern computers are so complex and fast that it gives enough entropy.
- larkeith 9y agoThis is wrong, on every count. Usage of microseconds as a seed trivialize the search space for the testing of potential seeds by an attacker. The speed or complexity of computers is irrelevant.
- minitech 9y agoThat’s dangerously wrong. If you generated a password using only microseconds as a seed, an attacker who knew the day you did it could crack (an MD5 hash of) the password within a few minutes, for example.
- solotronics 9y agoI bet they combine this with /dev/urandom or something to just add an element of chaos to something a computer generates
- schoen 9y agoA lot of confusion in this discussion thread and other promotions of this idea stems from the intuition that you can "run out" of entropy in your random number pool if you don't periodically replenish it with a physically unpredictable source. I have had this intuition too. Two things that feed it are the Linux random(4) man page and the behavior of GPG when generating a new private key. tptacek tried to explain some of the problems in this intuition at https://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers/ https://sockpuppet.org/blog/2014/02/25/safely-generate-rando..., which relates to why he's so annoyed at some things people have said in this thread (and when discussing CSPRNG seeding in other places). I like the idea of feeling physically unpredictable data into the CSPRNG, but for most purposes it's a misconception that doing so on an ongoing basis is in any way required by the design or that heavy users of randomness like CloudFlare would "run out of entropy" or "exhaust their entropy pool" if they didn't do so. The design of existing CSPRNGs would let CloudFlare use /dev/urandom for as long as it likes after securely seeding it just once, and there's no known cryptanalytic attack to which this practice would be vulnerable.
- Bromskloss 9y agoI've read that post now and previously (though not its references) and I feel that it never gets to the point where it explains how urandom can be equally safe as random. Is the idea not that it is information-theoretically safe, but rather that the computational requirements are too great to figure out the state of the random-number generator even after a large amount of observed output?
- schoen 9y agoYes, it's partly about comparing the security model of CSPRNGs to the security model of ciphers (and I think some of the CSPRNG constructions are extremely closely related to popular ciphers and hash functions). Part of the argument is that a cipher can encrypt an extremely large amount of data under the same key, and in the same way a CSPRNG can create an extremely large amount of pseudorandom output from a small seed. In some cases, deriving the internal state of the CSPRNG from observed outputs should be as difficult as deriving the secret key of a cipher from observed ciphertext or from known plaintext/ciphertext pairs. Maybe tptacek can do another go-round on this topic and make this more explicit (because he certainly still gets frustrated about people's intuitions when it comes up). There was something either in that piece or in another one by another crypto expert saying that if we don't believe that CSPRNGs have this security property, we shouldn't believe in the symmetric ciphers that we use them to generate key material for either, because they are constructed using the same kinds of techniques. I also don't remember what Matthew Green disagreed with Thomas about here.
- bmm6o 9y agoOne of my common daydreams is designing entropy-generating setups like this. Just last week I went on a brewery tour (Bell's) and stared at the bottling plant for a while, admiring the chaos of the bottles bumping into each other as the path turns and narrows.