17 ms·
These random/urandom blocking/nonblocking discussions have been going on for at least a decade at this point, maybe even longer. I get that RNG algorithms are h
by codeflo 5y ago
These random/urandom blocking/nonblocking discussions have been going on for at least a decade at this point, maybe even longer. I get that RNG algorithms are hard. What’s surprising to me is that it seems so hard to even figure out the desired interface of such a basic thing in the kernel. Security in entropy-starved environments seems to be very hard to square with backwards compatibility.
- staticassertion 5y agoI don't think it's hard to figure out the desired interface. As you said, the hard part is changing the interface to what's desired decades later.
- throwaway81523 5y agoYou'd be amazed at how much stupidity lingers about this issue. I don't know if the present-day kernel devs are affected by it, but an awful lot of users are.
- jonhohle 5y agoI ran into it the first time in 2005 and it was a widely known issue, easy to find if you could find where your program was pseudo-randomly blocking (pun intended). FreeBSD already had unified random/urandom by that point. I’m not sure if the Linux folks find something wrong with existing, time tested approaches or if there’s some NIH going on, but it doesn’t seem like a multi-decade problem.
- adastra22 5y agoPedantic question: would it be pseudo-randomly blocking or randomly blocking?
- mobiletoss1337 5y agoIt would be somewhat deterministic and predictable and therefore pseudo-random.
- jart 5y agoWhy is random so hard? If we assume best intentions then: uint64_t lemur64(void) { static uint128_t s = (uint128_t)426679527491843471ull << 64 | 2131259787901769494ull; return (s *= 15750249268501108917ull) >> 64; } Passes bigcrush and PractRand and it won't ever cause your system to hang on boot.
- noselasd 5y agoWhat it will also do is to allow anyone to predict your pseudo random numbers with high accuracy. (which is bad, as the use case here is for security)
- deleted 5y ago[deleted]
- aprdm 5y agoWhat kind of wizardry is this doing?! :)
- llimllib 5y agoSeems that's one of these: https://en.wikipedia.org/wiki/Lehmer_random_number_generator https://en.wikipedia.org/wiki/Lehmer_random_number_generator
- Dylan16807 5y agoIt's one of the simplest ways to make random numbers. Multiply state by a constant, return the upper bits/digits of state. There's some math that goes into picking a good constant, but honestly that's optional. Usually you'd also add a constant each round but this is going for absolute simplicity. And the line with 'static' is just an awkward way of initializing the state integer.
- tirpen 5y agoThose numbers are not random.
- tptacek 5y agoIt's not hard by itself. These interfaces are actually pretty straightforward to design and implement; Linux made things hard for itself by designing a weirdly complicated interface with an entropy credit system, an idea that's more or less discredited now. What's hard is accurately surveying the last 15 years of systems built on top of Linux's needlessly-complicated LRNG and making changes that don't violate the expectations of those systems. Nobody should be running "jitter entropy daemons" in userland (userland RNGs are essentially the source of all practical CSPRNG vulnerabilities in the past 2 decades), but people do, and if those systems exceeded some threshold of security before Donenfeld's patches, you can't merge those patches if they push security below that threshold. It's a really irritating problem.
- cperciva 5y agoan entropy credit system, an idea that's more or less discredited now ... no pun intended, I'm sure.
- tptacek 5y agoNope, just coming off a migraine and not catching stuff like that. :)
- yxhuvud 5y agoAlso,the problems seems mostly to be around Linux running in a VM rather than on actual hardware. Would it be possible to have the host urandom show up as a hw random number generator to the VM and then use that for initiating things? Seems less hacky than having to fiddle with seeds. Dunno how possible that is though.