4 ms·
Aggregating multiple sources of randomness has the potential to conceal bugs. In the Debian/OpenSSL bug from 2008 [1], randomness was sourced from multiple loca
by moonboots 13y ago
Aggregating multiple sources of randomness has the potential to conceal bugs. In the Debian/OpenSSL bug from 2008 [1], randomness was sourced from multiple locations including the current process id. The idea was that more randomness, even the minimal amount from the pid, could only increase the total entropy. However, when the primary source of randomness was eliminated through an overzealous patch, the PRNG still emitted plausible looking numbers due to the remaining sources of low quality entropy. Had the PRNG only used one high quality source of randomness, people would've noticed something strange about their generated private keys much sooner.
[1] http://research.swtch.com/openssl http://research.swtch.com/openssl
- contingencies 13y agoThat's an interesting take and does seem logical for human testing. However, it seems to me the real culprit was a lack of decent automated testing. More to the point, as well as the potential to conceal bugs it also offers the potential to mitigate the impact of bugs. This was the whole point of my question, which despite some interesting responses, basically remains unanswered.
- eru 13y agoIt is pretty hard to automatically test cryptography. (I do agree however, that C is a rather bad language for implementing cryptography.)
- contingencies 13y agoIt seems like there is an established test suite in the PRNG space, by NIST. http://csrc.nist.gov/groups/ST/toolkit/rng/documentation_software.html http://csrc.nist.gov/groups/ST/toolkit/rng/documentation_sof...