4 ms·
You are correct. However, history teaches us important lessons. Back in the old days when cryptography was a weird concept nobody understood, we had the Linear
by Genbox 4y ago
You are correct. However, history teaches us important lessons.
Back in the old days when cryptography was a weird concept nobody understood, we had the Linear Congruential Generator (LCG)[1] to generate pseudo random numbers. It looked random, so we used it.
Then some egghead said "give me a few outputs of your LCG and I can reverse it back to a seed"[2]. Oh damn! What do we do? The obvious solution: Reseed the RNG before you use it.
Then another egghead said "I've invented Mersenne Twister (MT). It is faster and more secure"[3]. So we switched to that. No need to reseed the RNG anymore!
But then someone said "We have broken MT. Take some numbers. Give it to this app, and it will give you the seed"[4]. And so we started to reseed the RNG again.
Today it is hash-chaining, XOR-shift and improved linear-feedback shift register algorithms.
Do you want to put your money on that we have now reached bug-free well-enough PRNGs that we no longer have fiddle with reseeding? It is a dangerous gamble. More than anything I wish we were clever enough to create robust, correctness proven and high-performance PRNGs so we could stop all this nonsense - but alas, here we are.
[1] https://academic.oup.com/comjnl/article/1/2/83/425243 https://academic.oup.com/comjnl/article/1/2/83/425243
[2] https://en.wikipedia.org/wiki/Marsaglia%27s_theorem https://en.wikipedia.org/wiki/Marsaglia%27s_theorem
[3] http://www.math.sci.hiroshima-u.ac.jp/m-mat/MT/ARTICLES/mt.pdf http://www.math.sci.hiroshima-u.ac.jp/m-mat/MT/ARTICLES/mt.p...
[4] https://github.com/altf4/untwister https://github.com/altf4/untwister
- eternityforest 4y agoXorshift, lfsr, Mersenne, and LCG were never intended to be secure as far as I know, and were never cryptographically broken because they were never secure to begin with. They discovered flaws that could bias some large scientific simulations and such in some of them. But nobody is going to be directly using USB numbers to make billions a second for simulations, these dongles are mostly meant for cryptographically secure stuff. Their competition is whatever algorithms Linux urandom snd OpenSSL are using at the moment, and the builtin RNGs most chips have had for a decade. CSPRNGs are occasional broken, but it seems to happen about as often as other crypto primitives. They are based on hashes and ciphers usually, and these days those can go for decades without much progress on a break. Unless P==NP or something happens and ruins all the fun, I'm fine with current crypto prngs. I don't think I've ever handled data that was so critical that anything else was needed.