13 ms·
maybe relevant ... https://lwn.net/Articles/961510/ https://lwn.net/Articles/961510/ (CPUs may have hrngs but there are certain observations on their behaviou
by fch42 3y ago
maybe relevant ...
https://lwn.net/Articles/961510/ https://lwn.net/Articles/961510/
(CPUs may have hrngs but there are certain observations on their behaviour that create concern)
- viraptor 3y agoI don't think that's what the post says. I understand it as: Hardware rng is not like csrng which is designed to pass validation. If you measure a truly random hardware rng for a long enough time, you'll get a string of 9s, however unlikely that is. It doesn't mean that that hrng is broken in any way.
- charcircuit 3y agoThat isn't it. When hardware rng is initialized it first runs tests on the randomness to prove that the hardware for getting entropy isn't broken. Then it feeds that entropy into a CSPRNG which gets exposed to code trying to use hardware rng. That person's point was that it's impossible to know for sure if entropy collection is broken. In practice it isn't an issue as you can make the false positive rate very small even if it can never be 0.
- fch42 3y agoI wasn't criticising hwrngs "as such" merely saying that actual evidence exists for some that their entropy pool can be exhausted and that they can degrade. "just use the cpu hwrng" is too-simple advice.