4 ms·
It may surprise you that the order matters - in the hands of a potential attacker, combining random sources is not commutative! If your last random source come
by qrmn 11y ago
It may surprise you that the order matters - in the hands of a potential attacker, combining random sources is not commutative!
If your last random source comes from an attacker who can read your state, then they can manipulate your state freely (XOR) or partially (any PRF), which could lead to trouble. Source: http://blog.cr.yp.to/20140205-entropy.html http://blog.cr.yp.to/20140205-entropy.html
Combining with a proper PRF limits the damage a bit compared to plain XOR, which is why Linux's /dev/random was changed to feed in RDSEED/RDRAND like any other entropy source.
On the other hand, there's the school of thought which says: if the CPU you're running on has been trojaned in hardware, you're probably buggered no matter what!