3 ms·
Use casino dice to generate the entropy, don’t trust the hardware. This is how I handle C-level authority keys in my company. Security is mostly about reducing
by DethNinja 6y ago
Use casino dice to generate the entropy, don’t trust the hardware. This is how I handle C-level authority keys in my company. Security is mostly about reducing the feasibility of the attack, there is no way to make your systems 100% secure but you can design it in a way that your 500k USD worth of system requires attacker to spend 5 million USD to breach it.
- pyinstallwoes 6y agoIf you had to have a unique address for every atom in the solar system (I avoided the Universe), what technique would you use? Still hash and casino dice for each one? I'm pretty serious with this question given contemplation of designing a future-inclusive Operating System.
- DethNinja 6y agoIf you really need so many cryptographic keys and won’t trust hardware then you have to build it yourself from commonly available parts and connect it to an offline raspberry pi to take out the automatically generated keys. An example on hand built entropy generator: https://github.com/nategri/chernobyl_dice https://github.com/nategri/chernobyl_dice You can do something like this for I guess 1000 dollars but it won’t be useable for real-time systems.
- pyinstallwoes 6y agoThank you for sharing your knowledge