4 ms·
The problem is "trusted" is as much a social construct as it is a technical one. For example, if you are an NSA employee, you might be utterly confident that t
by tytso 7y ago
The problem is "trusted" is as much a social construct as it is a technical one.
For example, if you are an NSA employee, you might be utterly confident that the NSA didn't twist Intel's arms to put in a backdoor into RDRAND --- e.g., that it isn't AES(NSA_KEY, SEQ++) --- and even if it were, you would be sure that as a US citizen, you would be safe from intrusive attacks to spy on your communications without a FISA warrent, which of course would only be done with a super scrupulous attention to legal process, the recent IG report of the Carter Page FISA warrant to the contrary.
In 2019, if you are a Republican member of the House of Representatives, such as Devin Nunes, you might be sure that the FBI is playing fast and louse with all FISA warrants, and so if so no one is safe from politically motivated investigations, especially if you are working for the Trump campaign, such as Carter Page.
See? Two different people might have very different opinions about whether a particular source should be trusted or not.
- upofadown 7y agoMy point is that you don't have to trust any particular source of randomness. NSA can backdoor RDRAND all they want. As long as there is a single legit source of randomness XORed in then the NSA is just wasting their time. So having options to remove some sources is pointless and can only make things worse, never better.
- tytso 7y agoSure, and that's why we still have the entropy pool in Linux. It's where we do the mixing. My apologies if I didn't understand the point you were making. And yes, I would love to see us adding more entropy sources in the future. The problem is I don't have a lot of time, and a lot of other projects to work on, but I've been trying to recruit people to add support to pass entropy from UEFI into the kernel (which requires changes to Grub, NERF, Coreboot, etc.), being able to pass entropy from one kernel to the next when using kexec, etc. I can't do it all myself; this is something that requires a lot of people to make things better.
- dependenttypes 7y agoCheck out https://blog.cr.yp.to/20140205-entropy.html https://blog.cr.yp.to/20140205-entropy.html Yes, xorring RDRAND with your existing secret can hurt security in certain cases.