Follow

"every device with a hardware random number generator (RNG) contains a serious vulnerability whereby it fails to properly generate random numbers"

labs.bishopfox.com/tech-blog/y

@lupyuen I implement all my RNGs as sequential counters. Technically speaking the output is valid and random if you just accept it is statistically unlikely , but not impossible, to be produced randomly.

The only stipulation is you can only run it once :)

@lupyuen that's a legit post! He talks up Linux /dev/urandom and that's pretty solid these days, but not too long ago there were a bunch of security key problems because the Linux random pool wasn't living up to its promises, and was giving back predictable "random" bits. May still be a problem on some low end SoCs!

dl.acm.org/doi/10.5555/2362793
factorable.net/

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.