4 ms·
You might want to check out this - https://docs.crp.to/security.html#cryptographically-secure-random-number-generator https://docs.crp.to/security.html#cryptogr
by cr7pt0 7y ago
You might want to check out this - https://docs.crp.to/security.html#cryptographically-secure-random-number-generator https://docs.crp.to/security.html#cryptographically-secure-r...
If you read further into the source you will see that analog read is only one of the sources of entropy, it uses capacitive touch from a user's skin and this TRNG passed dieharder tests - https://webhome.phy.duke.edu/~rgb/General/dieharder.php https://webhome.phy.duke.edu/~rgb/General/dieharder.php
- tptacek 7y agoPassing dieharder doesn't mean anything at all with respect to cryptographic security. It's trivial to define a random bit generator that passes randomness tests and has no real security.
- nemonemo 7y agoI would like to learn more about practical cryptographic issues, and I need some help: what are the tests that can prove or disprove stronger guarantees for cryptographic security of a PRG than diehard? A wikipedia page doesn't give me much info about which one provides stronger guarantee and in which criteria: https://en.wikipedia.org/wiki/Randomness_tests https://en.wikipedia.org/wiki/Randomness_tests Also, which level of security of a PRG is sufficient for keys like this?
- tptacek 7y agoThere aren't such tests, at least not that work like dieharder. You analyze a CSPRNG the same way you'd analyze a cipher construction (they are essentially the same thing, and often we draw our conclusions about the strength of a CSPRNG by noticing that it's built on and thus inherits the formal security commitments of ciphers and hashes run in modes and constructions that themselves have been shown to be trustworthy).
- JohnStrangeII 7y agoThere are no automated tests for this, since cryptographic randomness requires unpredictability. A statistical test can only tell you when a random number generator is broken, but no statistical test can tell you whether a random number generator is cryptographically sound.
- thinkloop 7y agoAnd so the only test is to analyse all known knowledge for any method that is capable of predicting some portion of the random numbers. If none exists, the process is "random".
- blattimwind 7y ago> what are the tests that can prove or disprove stronger guarantees for cryptographic security of a PRG than diehard? None. The difference between a good CSPRNG and a broken one might not even be in the construction at all, but in who knows the seed. For example, a keystream generated using Chacha20 or AES-CTR makes for a good CSPRNG... except if the attacker knows the key.
- TrueDuality 7y agoThe responses you've gotten so far are pretty bleak even if they are accurate. It's true that once you start mixing randomness, or get into algorithms the only thing statistical tests can really tell you is if it's broken. Those tests can be used on raw sources to learn about the quality of those inputs. In this case applying those tests directly to the analogRead() on a specific source of hardware (your entire circuit and manufacturing process will effect this, and will even vary from board to board) can give you an estimate as to how much entropy you can expect from each call. Understanding your where that entropy is coming from is significantly more important, gate voltage breakdown, fluctuations from the pins acting as antennas, in the current temperature and humidity is where analogRead() on a floating pin largely comes from. Other sources can be radioactive decay of particles, timing of events that are outside of the system (such as the time between a device being plugged in and the first time a person touches a key). These all provide small amounts of entropy (except for radioactive decay, that's a really good one). The next step is mixing entropy. There is a lot of good math showing that with proper mixing, even adding known inputs from an attacker into an entropy pool doesn't decrease the entropy in the pool (it's no less random). If time isn't an issue you can add in a large number of readings from the same source, though sampling faster than the source changes won't get you anything. That mixing allows you get to up to a minimum threshold of randomness (the seed) where you can use a cryptographically secure pseudorandom number generator (CSRNG). These also have proofs of a different type showing that input bits have an equal chance of modifying any bit of the output which can then be mixed back into the seed getting a very very large amount of effectively good randomness that can be used for keys and the like. The trick here is that you're effectively at war with attackers, the more of your entropy sources an attacker can predict or control, the weaker your overall input to the CSRNG is going to be. If they can get this down to a small possibility space they can predict the input to the CSRNG and in turn fully predict its output which will reveal your keys. If an attacker has a way to measure timings on the device a large number of times they may be able to infer the internal state of the system and once again get your keys. So it's not really about the quality of that final output that is the problem and that's largely what people doing these projects analyze with these tests. One final bit I'd like to cover. These tests can provide you some information about the final quality of the output (mostly whether it's broken or not) but even for that they're usually used incorrectly. If the CSRNG is implemented correctly but say you always seed it with the value "0", it will pass the tests with flying colors. For devices like these they should be fully reset, have a small amount of randomness output, fully reset, sampled again... thousands to millions of times. This will help you determine if the range of possible inputs to the system is inherently flawed and most projects I've seen (including this one) don't seem to do that.
- admax88q 7y agoYou cn literally run the number 0 through a modern hash function and pass dieharder without having any entropy.
- tripzilch 7y ago> Passing dieharder doesn't mean anything at all with respect to cryptographic security. Technically, doesn't not passing dieharder mean something with respect to cryptographic security, though?
- ctz 7y agoAccording to the K2x family guide, some devices have an hardware RNG available -- is it right this project uses a K20 without this? It seems pretty bad that merely grounding 8 pins on this device will reduces its entropy to basically to a handful of noise bits from the ADC?
- cr7pt0 7y agoYes it uses the K20, I think you may be confusing the threat model here. If you grounded the 6 capacitive touch buttons the device would not work at all so there would be no need for an RNG. The RNG is used for things like creating keys, in order to get to the point where you are creating keys you would have to be able to enter a PIN on your device by physically touching the capacitive touch buttons. As you do this the readings from your skin is input to the RNG. I hope this explanation makes it clear why this attack isn't possible. https://docs.crp.to/security.html#cryptographically-secure-random-number-generator https://docs.crp.to/security.html#cryptographically-secure-r...
- RL_Quine 7y agofor i in range(1,1000): print sha256("lol what's entropy" + i) This passes dieharder. Completely meaningless.