5 ms·
What's the best entropy bang--for-your-buck < $100?
by jdc 6y ago
What's the best entropy bang--for-your-buck < $100?
- pmiller2 6y agoMaybe this? https://www.amazon.com/dp/B01ENG4UX4/ https://www.amazon.com/dp/B01ENG4UX4/
- amenghra 6y agoFlip a penny twice, if you get heads followed by tails, write down 0. If you get tails, followed by heads, write down 1. Otherwise ignore the two flips. Rinse and repeat until you have enough bits. The purpose of flipping twice is that it offsets any potential static bias (caused eg by weight difference) between the two sides.
- amenghra 6y agoCommon ways to generate entropy in a way that’s friendly to computers include: measuring noise from a zener (or other electronic component), delta between two or more oscillators, or timing between external events (eg keystrokes, packets, etc). These are all super cheap to manufacture (~$1). If you want to go high end, you can spent ~$1000 and get a generator based on some quantum property (photon spin or background radiation detector). Computers will typically combine two or more sources of entropy. In newer tls version handshakes, the entropy from both, the server and client comes into play. So there’s ways to build defense in depth.
- faeyanpiraat 6y agoTruerng claims this on 100MB of generated data: Entropy = 7.999998 bits per byte. If you can fit this quality on a usb, why didn’t motherboards contain a circuit like that? Maybe they do on server boards?
- comex 6y agoThat's what RDRAND is - well, it's not the same physical mechanism as TrueRNG, but it is a fast hardware random number generator built into the CPU.
- wodenokoto 6y agoWasn’t there a paper that showed it is basically impossible to load a physical coin?
- gspr 6y agoAKA von Neumann debiasing, or the von Neumann trick.
- Q_is_4_Quantum 6y agoThere is a fun generalization of the game. Assume the penny has (unknown) bias p. You want to output a new flip with bias some function f(p). So f(p)=1/2 is what you described, ie how to get a fair flip. For some functions it can be even easier, e.g. f(p)=p^2 - definitely only requires two flips. How about: f(p)=p^2/(p^2+(1-p)^2) f(p)=2p(1-p) f(p)=3p(1-p) f(p)=sqrt(p) The last two are tricky, I took them from a paper "functions arising from coin flipping" by Wastlund. (The quantum generalization is even more fun, but this text box is too small to contain it.)
- ogre_codes 6y agoTwo are close I think. A capped webcamera, CCDs pick up enough stray electrons to be reliable source of entropy. A old cheap radio tuned to static plugged into your microphone port. https://www.mentalfloss.com/article/81946/7-sources-randomness https://www.mentalfloss.com/article/81946/7-sources-randomne...
- BelenusMordred 6y agoThis is not a good idea for the uninitiated and is on par with rolling your own encryption algorithm to send highly sensitive data around the world. For the price GP mentioned there's a dozen vetted opensource commercial options in the bottom half of that range.
- ogre_codes 6y agoThe uninitiated have zero business sending highly sensitive data around the world in general.
- BelenusMordred 6y agoAnd yet they still do it daily. This is why secure-by-default should always be the norm.
- saithound 6y ago> webcamera, CCDs pick up enough stray electrons to be reliable source of entropy. Ironically, this is the same setup as the lavalamps, but without having to pay for the lava lamps.
- ogre_codes 6y agoI believe they figured out the lens cap hack when there was a lava lamp failure.
- brodie 6y ago
- tptacek 6y ago$0, your base server or laptop, and getrandom.
- frob 6y agoRead the voltage drop across a high-value resistor at room temperature. There are random fluctuations proportional to the temperature and resistor value. You can use these fluctuations to generate unifromly distributed random numbers. https://en.m.wikipedia.org/wiki/Johnson%E2%80%93Nyquist_noise https://en.m.wikipedia.org/wiki/Johnson%E2%80%93Nyquist_nois...
- contravariant 6y agoJust set stuff on fire I suppose.
- BelenusMordred 6y ago> bang--for-your-buck Testing for randomness is impossible in the YES/NO sense, so the best we have is statistical test batteries like NIST's 800-22, DieHarder and TestU01. I own a Truerng and a Onerng, both are under $50. They performed better on Dieharder than my computer's Intel RNG. Not by a huge margin, but still. All 3 passed the minimum requirements of course.
- Spooky23 6y agoA set of casino dice and a 5 gallon bucket.
- dheera 6y agoJust hang a microphone outside your window and pick up all the birds chirping and other street noises?
- swirepe 6y agoI bet you could find some patterns in street noises, but I'm also not 100% sure what entropy is
- warent 6y agoI wonder if you could do this in a silent room with a cheap mic and just use the static white noise
- danielheath 6y agoI know someone who used that technique at one of the worlds largest banks, back in the 1990s.
- gentleman11 6y agoDice? https://www.eff.org/dice https://www.eff.org/dice
- JJMcJ 6y agoMulti-colored so your own biases don't affect the order you read the dice in. E.g., and I'm just guessing, some people might notice the higher numbers first and read those out.
- mightybyte 6y agoCasino grade dice
- dTal 6y agoAn ADC, the shittier the better. Turn the gain all the way up. Don't bother plugging a microphone into it. XOR all the bits together. Done.
- JJMcJ 6y agoDice - for not too many bits, and a low data rate. Hardware or /dev/urandom (or Windows equivalent) and downstream library calls - many bits, high data rate