4 ms·
It is xor'd because all entropy sources are xor'd. That's just the design of /dev/random. And because of this, Intel or whoever would need to have weakened eac
by necheffa 6y ago
It is xor'd because all entropy sources are xor'd. That's just the design of /dev/random.
And because of this, Intel or whoever would need to have weakened each and every entropy source you use to make anything of it.
- tremon 6y agoThat's not true, because the RDRAND entropy is mixed in last. So once you're under the assumption that RDRAND is nefarious, the microcode only needs to detect the rdrand-to-xor pattern to make the entire entropy pool predictable (for example: by setting the non-rdrand input to the xor operation to zero it could disable all other entropy sources).
- px43 6y agoA microcode backdoor capable of reading the existing entropy pool state is going to be a hell of a lot more powerful than a RDRAND backdoor, to the point of making a RDRAND backdoor worthless.