3 ms·
> a good PRNG should be able to eventually recover from compromise even if the entropy is injected into the system at a very slow pace I haven't gone through t
by d110af5ccf 5y ago
> a good PRNG should be able to eventually recover from compromise even if the entropy is injected into the system at a very slow pace
I haven't gone through the entire paper yet. Any idea what sort of threat model involves compromise of the PRNG state but not the entropy pool being used to refresh it? Assuming cryptographically secure functions it seems like being able to determine the internal state would necessitate low level access to the system so you could directly read it.
- tptacek 5y agoThis is considered at length in the commit message Jason links to; see upthread.
- d110af5ccf 5y agoSo effectively - initial key file leaked or otherwise duplicated between systems but system as a whole not compromised.
- loeg 5y agoThe whole of it seems to be (I'll split it into two sections): > If an attacker has access to the system to such a degree that he can learn the internal state of the RNG, arguably there are other lower hanging vulnerabilities -- side-channel, infoleak, or otherwise -- that might have higher priority. I think this probably matches most people's intuitions. > On the other hand, seed files are frequently used on systems that have a hard time generating much entropy on their own, and these seed files, being files, often leak or are duplicated and distributed accidentally, or are even seeded over the Internet intentionally, where their contents might be recorded or tampered with. Seen this way, an otherwise quasi-implausible vulnerability is a bit more practical than initially thought. This is a reiteration of "unpredictable initial seeding is hard."