3 ms·
One of the main threats that people have been worried about recently is global-scale passive attacks by the NSA. We know that they are gathering and retaining v
by lambda 13y ago
One of the main threats that people have been worried about recently is global-scale passive attacks by the NSA. We know that they are gathering and retaining vast quantities of data; that they don't consider it illegal to simply gather and retain data without a warrant of any sort, and only actually look at it later once they have a warrant or have a 51% confidence that at least one of the parties in the communication is foreign.
For this threat, most active attacks are not particularly useful. They may capture encrypted data at a different point in transit than the one that originated it, making most side channel attacks difficult or impossible.
But a compromised RNG can be almost impossible to detect, and yet render almost any crypto system trivially breakable offline after the fact. The NSA has already once created a DRBG for which there could be a secret key that could determine the internal state of the generator with only 32 bytes of its output http://www.schneier.com/essay-198.html http://www.schneier.com/essay-198.html
I agree that being too wary of your hardware can lead you down a rabbit hole of paranoia, and that on the whole, we have much bigger problems to solve than hypothetical backdoored hardware random number generators (I have not seen any evidence that Intel has included a backdoor, merely people saying that because it's a black box we can't tell that they haven't). But since a good RNG is absolutely essential to so much crypto, and a compromised RNG would make it so easy for an adversary who passively monitors all communications and would like to have the option to decrypt them at their leave at a later date, I think that this is more worth worrying about than problems with the AES instructions.