4 ms·
Background: I liked the xkcd-style password generation scheme as it was easy to remember, but existing generators online (that I could find, at least) all use M
by quantum5 6y ago
Background: I liked the xkcd-style password generation scheme as it was easy to remember, but existing generators online (that I could find, at least) all use Math.random() or other cryptographically insecure random number generators. While an actual attack on the RNG seems far-fetched, the very idea doesn't sit well with my crypto nerd side. So I decided to create my own that uses a CSPRNG that I can trust. This was a while ago.
Recently, I decided to package it up with a nice domain name and publish it in hopes that it would be useful to others.
- perl4ever 6y agoWhat about https://www.random.org/ https://www.random.org/? Why even use a PRNG if you can have the real thing?
- quantum5 6y agoBecause instead of just trusting your system, you'd also have to trust an external service to remain honest. CSPRNG is widely deemed acceptable for use as key material (unlike standard PRNGs), so there is no reason to add an external dependency.
- atoponce 6y agoFurther, sufficiently seeded cryptographically secure RNGs are indistinguishable from true random white noise, so from a practical perspective, there is no point to require "true random".
- perl4ever 6y agoThat seems like a false dichotomy to me unless I were to truly understand the PRNG.
- 1e-9 6y agoThere is always the risk that such a website is, or could become, malicious and save generated numbers for future attacks; or, it could suffer from a hardware, software, or environmental issue that reduces entropy. While I would not fully trust a website-generated random number for anything important; you can XOR a number from a website such as www.random.org with a number from your system's PRNG so that you don't have to fully trust either. Even better, you can XOR again with some dice-generated numbers, your own custom PRNGs, or whatever else you can think of. That way, as long as at least one subset of your sources has sufficient entropy, you are safe.
- Jaruzel 6y agoNice idea. Not sure I'm going to remember the 9,999 word password it just generated for me :)