3 ms·
If they actually integrate this into randomness on their TLS servers, the only risk is that the system for getting the entropy from the lamps and waves somehow
by dadrian 2y ago
If they actually integrate this into randomness on their TLS servers, the only risk is that the system for getting the entropy from the lamps and waves somehow screws up, fails to parse an HTTP request or something, and accidentally seeds the whole system with no entropy. Whereas doing literally nothing and just letting Linux boot correctly on metal would be perfectly secure.
- tptacek 2y agoRight, but there's no way Cloudflare is making that kind of mistake. If it was a random person on HN talking about how they'd hooked up a bespoke hardware RNG to their TLS stack I'd write some tut-tutting thing about what could go wrong, but here the security of their system collapses down to the LRNG just like every else's.