6 ms·
I inadvertently spawned this discussion by pointing out that many open source security projects like Linux, OpenSSL, GnuTLS, libgcrypt, dm-crypt, etc. all depen
by sweis 13y ago
I inadvertently spawned this discussion by pointing out that many open source security projects like Linux, OpenSSL, GnuTLS, libgcrypt, dm-crypt, etc. all depend on closed-source crypto implementations [1]. This was followed by one of the Linux guys saying he quit the project over RdRand [2].
Everyone seems to be missing the point: RdRand is the least of your worries. If you can't trust the CPU, you can't trust it to multiply correctly, much less perform crypto.
If a CPU maker or OEM wanted to be evil, they wouldn't even need to bother backdooring the hardware. SMM or microcode updates would be much easier to compromise.
[1] https://mailman.stanford.edu/pipermail/liberationtech/2013-July/009946.html https://mailman.stanford.edu/pipermail/liberationtech/2013-J...
[2] https://mailman.stanford.edu/pipermail/liberationtech/2013-July/009969.html https://mailman.stanford.edu/pipermail/liberationtech/2013-J...
- deleted 13y ago[deleted]
- ig1 13y agoIt's about verifiability, you can verify if a CPU is multiplying incorrectly, there's no way of verifying if the random source is generating randomness correctly.
- tptacek 13y agoYou can verify that your CPU is multiply correctly at one moment in time.
- ig1 13y agoYes, but active attacks where a third-party can switch on-and-off features on your CPU are obviously vastly different from a passive attack such as a compromised random number source. The RNG attack suggested can pass verifiability while at the exact same time introduce a backdoor and thus constantly be on.
- pbsd 13y agoAre you ready to test all the 2^128 possible multiplications your CPU can do?
- ig1 13y agoIntegers form a closed group (in the group theory sense) under multiplication and addition, so if you were concerned about specific calculations being compromised you could verify the answer via alternative calculations and testing for consistency. Faking consistency is likely impossible without causing a huge amount other calculations (which the CPU will do as part of day-to-day operations) to fail.
- B-Con 13y agoNot an expert, but in theory the CPU can detect specific contexts and change its behavior. If side-channel attacks can detect AES operations, the CPU can do an even a better job.
- fragmede 13y ago> you can't trust it to multiply correctly That did happen at one point, and cost Intel an estimated $475 Million[1]. Of course, that was (presumably) an unintentional bug. [1]http://en.wikipedia.org/wiki/Pentium_FDIV_bug http://en.wikipedia.org/wiki/Pentium_FDIV_bug -- I don't consider SMM or microcode updates to be above suspicion; Ken Thompson's's Reflections on Trusting Trust suggests that nothing is above suspicion.
- yuhong 13y agoDon't forget early 386 steppings too. Remember the double sigma?
- joshuak 13y agoBut what if the government, specifically under the argument of national security, wanted a chip manufacturer to use a specific algorithm? They may want to do this not to create a general weakness or backdoor. That is to say not a backdoor that just anyone could use, but a specific backdoor that only the NSA (not even the chip manufacturer) knew. Such a back door could be accomplished with tools like Dual_EC_DRBG (http://en.wikipedia.org/wiki/Dual_EC_DRBG http://en.wikipedia.org/wiki/Dual_EC_DRBG).
- tptacek 13y agoNSA does not need a ludicrously inefficient RNG design to backdoor your crypto.
- joshuak 13y agoReally, because they have a better way? Either they are just dumb and designed Dual_EC_DRBG by accident, or they design systems like that for a purpose. Your assessment of what they need is an assertion, based on what exactly? Security is designed not around what one thinks an attacker needs, or why they would want do do something. It's about preventing an attacker from getting access to things a person wishes to keep secure regardless of why they would want to. In that light weaknesses in random number generators is a relevant field of inquiry. Otherwise simply ignore cryptography altogether, trow up your ands and say why bother.