4 ms·
Random numbers are used to generate your TLS certificate key or your SSH key. If one can predict how a TLS or SSH key was generated they could impersonate the k
by acatton 3y ago
Random numbers are used to generate your TLS certificate key or your SSH key. If one can predict how a TLS or SSH key was generated they could impersonate the key holder.
Here is an explanation of what was possible when a Debian packager mistakenly introduced a patch which reduced the SSL certificate keyspace in 2008: https://jblevins.org/log/ssh-vulnkey https://jblevins.org/log/ssh-vulnkey
The possibilities of keys which were generated by this random number generator was so small, that a brute-force attack on keys was feasible.
That being said, for years, random number generators have been using random signals coming to your computer (key strokes, network packets, ...) and feeding them into a sponge function. You don't need lava lamps or pendulums to generate random numbers, it's just for the press.
https://www.2uo.de/myths-about-urandom/ https://www.2uo.de/myths-about-urandom/
- tetha 3y agoSpeedrunners abuse this in a fun way on older consoles, RNG manipulation [1]. For example the SNES had no actual source of random numbers, so games had to use the inputs as the most unpredictable random source. However, if you do that, people figure out how you can scroll through a menu to force an item to drop or an attack to become great[2] If implemented in full tool assisted speedruns, this can become entirely ridiculous. That rare thing you need to grind hours to find? nope. just press these 18 buttons starting at the right frame and it'll drop first try. 1: https://www.youtube.com/watch?v=MNQaZFwu57E https://www.youtube.com/watch?v=MNQaZFwu57E 2: https://www.youtube.com/watch?v=-sfE8qLCnQY https://www.youtube.com/watch?v=-sfE8qLCnQY
- tialaramex 3y agoNintendo's relatively modern Mario Maker 2 even deliberately chooses not to have real randomness. "Random" MM2 courses such as "Carlsino" actually rely on subtle differences in player inputs, if you could ensure you don't deviate from a certain series of button presses and timings then the "random" elements would always turn out the same.
- tetha 3y agoAye. It is a very interesting question if you need or even want full randomness in a game. If you have something that's geared towards speed running, fast execution and mastering, being deterministic is actually a good thing. Otherwise, the player has to re-roll a hundred times to get the "good seed" to get a good run - that's very frustrating. Look at some of the kings quest speedruns for this kinda frustration. Or in a similar direction - tetris with a true random piece selection can result in very frustrating and unwinnable piece sequences (which bastard tetris is dialing to 12). Instead, quite a few modern implementations choose some set of tetrimonios and fill a bag with 3-5 repetitions of this set and choose from that. This limits the possibility and length of possibly frustrating pieces.
- tialaramex 3y agoConventionally speed running communities define their own categories. So as long as there's some way people can agree for how to compete things work out OK. You'll see that for example several important speed running games have "No major exploits" in a category rule - who decides what's a "Major exploit" ? The other runners, duh. At a GDQ it's fun to watch some awful exploit "win" Mario in eight seconds (not a real example) by messing with a game bug and precise input, but it's also fun to watch somebody who is incredibly good beat it the way you'd imagine you could if you were much better at the game, so there's room for multiple categories in popular games. If there's a split it can often be resolved by having two categories. If you think it's stupid to hope to get a good seed in Minecraft, you can just only run the chosen seed categories, meanwhile if you think that sucks because it doesn't reward agile thinking you might prefer the random only categories. Both groups get to have fun.