8 ms·
I might be prejudiced, but this looks like a big PR stunt/done for the cool factor kind of thing. Aren't there simpler/saner alternatives for getting good rando
by samuel 9y ago
I might be prejudiced, but this looks like a big PR stunt/done for the cool factor kind of thing. Aren't there simpler/saner alternatives for getting good randomness?
- Houshalter 9y agoWhat would be an easier way? A wall of lava lamps seems pretty easy to set up.
- comboy 9y agobusy streets webcams?
- MBCook 9y agoThat would be susceptible to traffic patterns.
- firethief 9y agoNot meaningfully. The input doesn't need to be uniform, just unpredictable. Statistical patterns are fine, as long as no one can predict exactly what's going to happen (to the pixel level). Even if all the drivers on the road were collaborating, they couldn't coordinate well enough to feed the camera adversarially predictable inputs. At least, not human drivers...
- MBCook 9y agoI was thinking more along the lines of busy/non-busy times may affect how much random data you get at different times of the day/week. Not specifically some sort of giant coordinated attack to modify the randomness generated to specific values.
- comboy 9y agoCars don't look exactly the same and are not in the exact same places. Lighting changes. People look very different and walk different paths. It's going through PRNG so even very small pixel differences (which you can find even on an empty street thanks to changing weather, litter, wind and so on) are good enough if they are unpredictable. In other words, when you compare pictures of the same lava lamp with pictures of some random cars, I think you will be able to find more patterns in the lava lamp movement. You would also likely be able to predict it better (well that's the same thing I guess).
- Quenty 9y agoMy guess is there’s still enough noise it doesn’t matter.
- twic 9y agoPut a fountain in the lobby and have a microphone listening to the splashes.
- psychometry 9y agoThere are an infinite sources of random audio out there that aren't susceptible to human interference.
- pvg 9y agoThe zillions of sources of EM/thermal/etc noise. It's so prevalent, most of the time the effort is spent in trying to get rid of it.
- blattimwind 9y agoVery wideband Zener noise sources are a common piece of measurement equipment; and many folks built their own noise sources (also for RNGs) using Zener junction breakdown. While building my own I needed quite a bit of shielding to avoid interference issues by RF sources (mostly HF fluoerescent lights and LEDs), so these sources might be susceptible to bias by EMI...? Other junction breakdowns have noise as well, resistive noise is very low power. Atmospheric noise and background noise is a thing too, but I'd guess they are too susceptible to interference by malicious actors...
- pvg 9y agoSuch sources are always post-processed to deal with bias and correlation. No sane implementation just takes the straight measured output, whether it's keyboard interrupt timing or radioactive decay.
- jakobegger 9y agothe random noise from the camera sensor is plenty good randomness. It would work just as well without the lava lamps.
- ScottBurson 9y agoIf you want the same kind of visual display but with much lower power consumption, a much higher bit rate, and better reliability, I'd suggest a few plasma spheres, e.g.: https://www.scientificsonline.com/product/nebula-plasma-ball https://www.scientificsonline.com/product/nebula-plasma-ball
- rm999 9y agoFor sure. In another office they use a geiger counter (a much more standard way to get randomness, and probably easier to setup). That said, this doubles as a public art installation in their lobby - something many companies spend thousands (or millions!) of dollars on. So it's not just PR, it's actually surprisingly practical.
- Sir_Cmpwn 9y agoI know I'm nitpicking here - it's a private art installation.
- gregschlom 9y agoAnyone can visit it though, according to the article.
- azinman2 9y agoA private collection doesn’t mean the outside world isn’t allowed to visit. It just means it’s not owned by a public institution.
- jstanley 9y agoIf it was a public art installation, wouldn't that leak their entropy?
- kaycebasques 9y ago> this looks like a big PR stunt/done for the cool factor kind of thing Probably, but it is indeed pretty cool. I appreciate when people take something potentially mundane and bring style to it.
- shagie 9y agoI suspect its a matter of getting a lot of random rapidly with easily replaceable and unregulated devices. The classic HotBits ( https://www.fourmilab.ch/hotbits/ https://www.fourmilab.ch/hotbits/ ) uses radioactive decay to get its random data. This generates 100 bytes per second of randomness. But that also depends on getting a radiation source. A single one costs about $80. A lava lamp costs $10. Working off the list of isotopes that they provide, You've got things that have half-lives. The issue there is that the way that one generates random data from radioactivity is get an event (A), and then get another event (B) and another event (C). The time between A and B is compared to the time between B and C. If AB is shorter than CD you've got a 1. If its longer than you've got a 0. If its the same, then throw about AB. As the material decays, its rate of generating bits of data slows down. Lava lamps are easily replaceable and don't have half-lives. I suspect there's also issue with "here is our lead lined vault where we keep a bunch of radioactive disks to generate random data". Sure, the units are micro Curie (the most active one is a 10uCi Cesium 137). But... do you want to go into that room and change a burnt out detector? How about swapping out a lava lamp because of a burnt out bulb?
- gruez 9y ago>As the material decays, its rate of generating bits of data slows down. can't you use something with a really long half-life?
- noir_lord 9y agobut then your initial rate is much slower.
- adam_w_02125 9y agoSo get more material!
- deleted 9y ago[deleted]
- 9y ago
- tptacek 9y agoIt is entirely, 100% a publicity stunt with no practical importance whatsoever.
- mbesto 9y agoYes, the article and the form in which it is exhibited is a PR stunt. However, that doesn't mean it's not practical in any capacity....if you locked this away in a room and never told anyone, it would still hold a utility for the company. Are there alternatives? Sure, but again that doesn't make it impractical. It's also a fairly novel way to explain to people that `random()` isn't truly random.
- tptacek 9y agoIt is unlikely that it holds any utility, or that it is practical in any capacity.
- cmpxchg 9y agotptacek is right. It's a cool art installation, but for practical purposes this is utterly useless. A modern hardware RNG (which is entirely silicon based) generates random bits at a vastly higher rate, and with better reliability, like built-in continuous statistical tests, than something rigged together with lava lamps, Geiger counters or the like. I've built those kinds of science projects, and they are great for fun and for learning, but they are not practical or necessary in any production environment.
- mbesto 9y ago> but they are not practical or necessary in any production environment But do they provide any greater advantage or greater utility to your "science projects" other than being cheaper to run? What do higher rates and higher reliability have to do with being able to create a non-deterministic and thus truly random bit? In other words, how on earth would a hacker even conceivably be able to hack the lava lamp setup?
- 9y ago
- pns 9y agoSee cloudflare blog post conclusion - they're quite aware it's hopefully unnecessary and possibly just a flair factor (their pun :) but may help prevent an attack ever so slightly. "Hopefully we’ll never need LavaRand. Hopefully, the primary entropy sources used by our production machines will remain secure, and LavaRand will serve little purpose beyond adding some flair to our office. But if it turns out that we’re wrong, and that our randomness sources in production are actually flawed, then hopefully LavaRand will be our hedge, making it just a little bit harder to hack Cloudflare."
- tptacek 9y agoYou know, that, or actually fuzzing their proxy code.
- Waterluvian 9y agoThe best kind of fun is good clean wholesome fun. I love when we take a "detour" at work to do something in a fun way.
- BurningFrog 9y agoIt looks quite simple and sane to me. A big plus over the alternatives I see mentioned is that you can easily see if it's working right now. What bothers me is that at least 80% of the wall is unrandomized wall and lampfeet.
- stouset 9y agoDoesn’t matter. As a simplistic example, if you send the image through SHA-256 it doesn’t matter how many bits are predictable — as long as there are at least 256 bits of entropy in the image, the output will have those 256 bits of entropy smeared across the output evenly (barring breaks in the hash function itself).
- itronitron 9y agoUnfortunately they're not cool, a single lava lamp puts off a lot of heat, I can't imagine the heat generated from a wall of them. Seems like you could get similar randomness from a wall of betta fish and have a lower electricity bill.
- nwallin 9y agoThere are plenty of simpler sources of high quality randomness. The important bit is whitening. Virtually all measurements of anything are not as precise as the number of bits used to represent the sample. Virtually any sensor measuring real world data will be imprecise in the last 1-4 bits. Take 256 raw samples from virtually any real world sensor, run the raw data through SHA-256, voila, you have 256 random bits that's secure against the overwhelming majority of hackers. Take 256,000 samples, run the raw data through SHA-256, now you have 256 random bits that's secure against the NSA. Cameras are great for this, but first you have to ensure that you're getting the raw data and not an image processed with HDR or jpeg compression or whatever special sauce Google/Apple do these days, and you also have to test to ensure that the image isn't overexposed. If it's an 8 bit sensor and all pixels are pegged at 255 you don't have useful randomness. Although the opposite isn't true: it's impossible to peg all pixels at 0. You'll always get values of 1-10 or so with the same pixels fluctuating +/- 1 or so, even in a perfect darkroom with perfect insulation from cosmic rays and background radiation. The average smartphone is packed full of gadgets that could be used to generate random data after running it through whitening. Accelerometers, magnetic compass, capacitance of each pixel of the touch sensor, all the radio antennas pulling atmospheric noise, (CDMA, GSM, GPS, bluetooth ...) microphone, camera... The lava lamps themselves might make the process more efficient, because now some of the higher order bits are random as well. But honestly, from a realistic security standpoint... they're just as well off taking pictures of a blank, uniformly lit white wall. As long as they do whitening properly. edit: It's still super cool though. Just not... in terms of temperature. It's probably really hot.