3 ms·
You still need some way to securely seed a CSRNG. That's what we use the entropy pool for in Linux. The idea is that we mix multiple sources, and hopefully a
by tytso 7y ago
You still need some way to securely seed a CSRNG. That's what we use the entropy pool for in Linux. The idea is that we mix multiple sources, and hopefully at least one can't be guessed by a particular attacker.
For example, you might use three hardware random number generators; one might be compromised by the Chinese MSS, and one might be compromised by the KGB, and the third might be compromised by the NSA --- but hopefully they won't be all compromised, and even if they are, hopefully they aren't working together.
Or maybe we're mixing randomness from the UEFI and the TPM. Neither can be audited, and we know that many firmware engieners are incompentent. But hopefully, if the UEFI BIOS has some terrible bug, or can be remotely compromised because Intel snuck in a Minux OS with a web server without telling us in their CPU's, maybe the TPM provider didn't make a similar mistake.