Really Random Number Generator
makezine.com
makezine.com
The one reaction I have to share is neither here nor there, but there's a sentence suggesting this is great for games. The two problems you'll have applying something like this to games are 1- the bandwidth of this RNG is much slower than your laptop CPU. It'd pair very well with a game running on the Arduino you build the RNG with though. :) 2- I've done a lot of game programming, and came to the conclusion that I almost never wanted a random number stream. They cause repeats way too frequently. Every time I want "random" behavior in a game nowadays, I generally either pre-generate a set of behaviors randomly and then shuffle them (guaranteeing you see each behavior once before any repeats) or use an even uniform sampling in a cycle. It was a little surprising at first, but I definitely have a better appreciation now for why game mechanics with some repetition (or maybe "predictability" is a better word) are more fun than true technically 'random'.
http://makezine.com/projects/electronics-fun-and-fundamental...
So you know how you hate it when your music player is on 'shuffle' and it plays the same song twice in a row? OP is saying people experience that it games too, and I think that's perfectly plausible.
If I have a 10% chance of missing, there's a 1% chance of missing twice in a row.
If I have a 25% chance of missing, there's a 1.5% chance of me missing 3 times in a row, and if I sit there for an hour with my finger on the trigger this is going to happen rather a lot. What I'm going to remember is that 'all the time' I just miss the same dude and he nearly kills me and I don't like this game.
There's probably an elegant way to do that in hardware (but I'd have no idea).
And if you really do need unpredictable numbers for your game (e.g. online gambling, where good randomness is a security requirement), it's far more practical to use a CSPRNG, especially since one is built into your OS. The practical difference is negligible. If an attacker can predict /dev/urandom, we've all got much bigger problems.
One of my favorite bits of statistical math is the 2d6 phenomenon. That you can get a normal distribution simply by summing two random numbers together. If you want 1-10 but most of the numbers in the middle, do (random(1-10) + random(1-10))/2
Here's an alternative which is slightly more paranoid.[1]
[1] https://www.tindie.com/products/WaywardGeek/infinite-noise/
https://en.wikipedia.org/wiki/Lavarand
And its site in all its Web1.0 glory: http://web.archive.org/web/20010926221159/http://lavarand.sg...
For microelectronics there are better ways for true digital random number generators, e.g. http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.99....
https://github.com/id-Software/DOOM/blob/77735c3ff0772609e9c...
1: https://github.com/pwarren/rtl-entropy
2: http://blog.cros13.net/2014/08/cheap-entropy-using-your-rtl-...
3: https://pthree.org/2015/06/16/hardware-rng-through-an-rtl-sd...
Other than that you wouldn't.
I guess you could argue governments all over the world are looking at chacha20, where as this has security through obscurity, which has value.
But on the other side being handmade hardware it'd be much more likely to have flaws which analysis of the data might find rather quickly.
Of course if you really cared you'd just buy a real TRNG.
But then you have a blackbox and are forced to trust the manufacturer.
(And as the Snowden revelations show, you have to care about man-in-the-middle attacks over the postal system, while that blackbox is on the way to you.)
To add some tinfoil-hat mentality on top of that: I believe it is easier to manipulate a blackbox TRNG than it is to manipulate individual components (transistors, etc.).
So although the DIY approach has the downside that you may get things wrong, it has the upside that it is very hard to manipulate.
The output from the entropy sources are mixed using SHA-512 before being used to seed ChaCha.
The Cryptech TRNG has been and is continiously tested. The current development will add test functionality to provide online monitoring of the entropy sources as well as the final output from ChaCha.
There will also be a specific test mode to allow user applications to insert its own "entropy" and extract generated seed as well as providing test vectors for ChaCha. In this way it will be possible to verify that the TRNG works during production, but also verify that the digital chain is in fact working as specified.
For more see: http://wiki.cryptech.is/wiki
(Disclaimer: I am the main author of the Cryptech TRNG.)
Still, very cool project though!
I dunno, maybe it's two different, equally valid attitudes. I guess I dislike it for the same reason I prefer C++ over Java.
Also, if we're going to be pedantic, I'd recommend a FET over a voltage divider.
NeuG is an implementation of a true random number generator, a tiny USB 32-bit computer based on a free (as in freedom) hardware design.
This diagram is a dog's breakfast. The draftsperson apparently thought this style would make the circuit easier to construct, and perhaps it does, but their real job was to make the circuit easier to understand, and that definitely didn't happen.
BTW for anyone copying this onto a breadboard, I've never seen one where the busses are split like the picture. Make sure your 5v and 18v aren't actually connected! Perhaps by building in the middle of the board if the bus is split there.
FWIW I generally just leave those bridged and a healthy supply of decoupling and supply caps as things that just stay on the board. Circuits that want more than 2 rails + ground get built on a larger board consisting of multiple basic boards, so there's never a need to pack things in.
So, I guess CamperBob2 is right that it's optimized for building rahter than theoretical analysis. Usually the text does a pretty good job of explaining his circuits.
The electronic design described in the article is a _true_ random number generator.
http://www.cryogenius.com/hardware/isarng/diehard.txt
The hardware generator passes more diehard tests than the LCG. In any case, a true-RNG scheme is supposed to feed into a PRNG. True RNGs feed into sources of entropy, and then you use entropy sources as part of PRNGs to extract more randomness out of them (if you need speed).
Or not... if you need "security". (Stay slow, so you get tons of entropy)
> a standard pseudo-random number generator is faster
This hardware RNG doesn't require a CPU at all. Its an electronics project that can feed into anything.
It makes almost no sense to compare a hardware solution against a software one.