10 ms·
For sure. In another office they use a geiger counter (a much more standard way to get randomness, and probably easier to setup). That said, this doubles as a
by rm999 9y ago
For sure. In another office they use a geiger counter (a much more standard way to get randomness, and probably easier to setup).
That said, this doubles as a public art installation in their lobby - something many companies spend thousands (or millions!) of dollars on. So it's not just PR, it's actually surprisingly practical.
- Sir_Cmpwn 9y agoI know I'm nitpicking here - it's a private art installation.
- gregschlom 9y agoAnyone can visit it though, according to the article.
- azinman2 9y agoA private collection doesn’t mean the outside world isn’t allowed to visit. It just means it’s not owned by a public institution.
- jstanley 9y agoIf it was a public art installation, wouldn't that leak their entropy?
- Operyl 9y agoYou’d have to get a picture in the exact same angle, which is unlikely.
- jstanley 9y agoIt leaks information at any angle.
- stouset 9y agoDoesn’t really matter. With modern CSPRNGs, even if one input is compromised you’re still as strong as the remaining entropy (as long as those sources are statistically independent from the compromised one). If this was the only source of randomness it might be a problem, but if they’re `cat`ting it into `/dev/random` as an external source, it can only really improve things. Even if someone were to compromise the feed from the office to the datacenter, it wouldn’t matter since they’d have to know the internal RNG state in order to “negate” its randomness with the lava lamp feed. If they have that, you’re already lost anyway.
- code_duck 9y agoYou’d also have to be using very similar equipment and know precisely how they derive their random numbers from the image.
- meej 9y agoThis is addressed in the last paragraph of the article.
- jstanley 9y agoNot really. They say that having random (ha) people in the picture improves the entropy, but they don't address the possibility of people using it to gain information about Cloudflare's entropy pool.
- notatoad 9y agopresumably if you set up camp with a camera in their lava lamp room, somebody is going to raise some eyebrows.
- gerdesj 9y agoNot only that but your cameras are going to have to be precisely in the same place as theirs, with an identical view and be identical models with identical sensor variation, dust on lens etc etc etc ad nauseam. As you say, that might raise a few eyebrows.
- frankydp 9y agoWouldn't you just cover their camera with paper or some other known pattern, if you were going to try that?
- IgorPartola 9y agoOoh! Can you shine a laser into the camera to blind it? Burn the sensor to a crisp and then let that seed the CSPRNG!
- mygo 9y agoGreat way to test how quickly you can get thrown out by security guards
- disillusioned 9y agoShort of them actually publishing the image signature the camera takes as the random input, no. Imagine just how much sensor noise is sitting across the image, and figure on other elements others have mentioned: the angle, the aperture, etc. I imagine two near-identical frames without any movement between them taken on a single camera might still have a significant amount of entropy between them, especially if you're using the camera raw data, for those reasons. They (CF) discuss this on their deep dive: >>>The flow of the “lava” in a lava lamp is very unpredictable,6 and so the entropy in those lamps is incredibly high. Even if we conservatively assume that the camera has a resolution of 100x100 pixels (of course it’s actually much higher) and that an attacker can guess the value of any pixel of that image to within one bit of precision (e.g., they know that a particular pixel has a red value of either 123 or 124, but they aren’t sure which it is), then the total amount of entropy produced by the image is 100x100x3 = 30,000 bits (the x3 is because each pixel comprises three values - a red, a green, and a blue channel). This is orders of magnitude more entropy than we need. [1] 1: https://blog.cloudflare.com/lavarand-in-production-the-nitty-gritty-technical-details/ https://blog.cloudflare.com/lavarand-in-production-the-nitty...
- jstanley 9y agoIf the information encoded in the lava lamps is not important for the entropy, why do they even need to be there? If it just needs to be some image, and it doesn't actually matter if others know what it can see, why not just point the camera at a normal lamp, or an empty room, or the sky?
- crazyhatfish 9y agoIt is, the author is just saying that even without it they still have enough entropy in the system to be secure enough. Any old image doesn't have pretty strong random number generators in it.
- thriftwy 9y agoGeiger counter might happen to be very vulnerable to collocated attacks. Overwhelm counter with non-random radiation, compromise a batch of keys produced during the burst,
- shagie 9y agoAre you suggesting a gamma ray beam? Or neutron beam? (You couldn't do an alpha particle beam - that's stopped by a sheet of paper... and the beta particle ray would have difficulty with the building construction). This then goes to the question of "where are you getting a focused gamma ray beam that has sufficient rate that you're able to modulate the period between two detection events?"
- thriftwy 9y agoThis depends on what the counter in question is measuring. If it's "background" radiation, where background is outside the counter, it should be pretty easy to bring your own foreground. If it's an internal source and it is properly shielded, this becomes much harder.
- shagie 9y agoEven if you did either of those... the bits (at least the hotbits algorithm) works off of the detection of multiple events. Bringing in some Iodine 128 into a place (half-life of 25 minutes) into the area, that would change the rate of bit generation, but not actually influence the bits themselves. Lets say you've got some cesium that's creating 800 bits per section. That one (now that I go back and read it closely) is based on four events: E1 <-(T1)-> E2, E3 <-(T2) -> E4. If the time between E1 and E2 is less than the time between T3 and T4 - its a 0. If its greater, its 1. Bringing in some other source wouldn't change that algorithm unless one could control the "when" to some degree so that the gigercounter detects your events with greater frequency than the other source... and at that point, you might as well unplug the gigercounter from the com port and feed in your own data. This could be done with background radiation too - but that's many fewer events and so a lower rate of germination. The time between two events is random and will remain random even with more radioactivity in the area.
- deleted 9y ago[deleted]