Encryption Lava Lamps (2017)
atlasobscura.com
atlasobscura.com
So-called "physically unclonable functions" https://en.wikipedia.org/wiki/Physical_unclonable_function
I am immensely skeptical of these, but they have some academic and other obscure traction.
The relationship to lava lamps is PUFs are a physical instead of a logical source of data, conceptually not unlike a quartz crystal in a clock, or radio active decay for random numbers, or even biometrics for authentication. You take something physically natural then sample it at a given interval to get logical data within certain parameters.
The security of such a system is not in the mystery of the physical object, but the sampling scheme. Apropos of the news, just like it isn't important so much who people vote for, it's who counts the votes that matters. The security of both lava lamp RNGs and PUFs are subject to an analogous sampling dynamic. So are biometrics.
IIRC major challenges included ensuring and proving randomness, stability of bit patterns over time, and general longevity of the whole chip.
The alternative to it is to just generate the key and write it at some point in the chip production line, and that’s generally considered good enough, so...
The purpose of flipping twice is that it offsets any potential static bias (caused eg by weight difference) between the two sides.
Computers will typically combine two or more sources of entropy. In newer tls version handshakes, the entropy from both, the server and client comes into play. So there’s ways to build defense in depth.
Entropy = 7.999998 bits per byte.
If you can fit this quality on a usb, why didn’t motherboards contain a circuit like that?
Maybe they do on server boards?
How about:
f(p)=p^2/(p^2+(1-p)^2)
f(p)=2p(1-p)
f(p)=3p(1-p)
f(p)=sqrt(p)
The last two are tricky, I took them from a paper "functions arising from coin flipping" by Wastlund. (The quantum generalization is even more fun, but this text box is too small to contain it.)
A capped webcamera, CCDs pick up enough stray electrons to be reliable source of entropy.
A old cheap radio tuned to static plugged into your microphone port.
https://www.mentalfloss.com/article/81946/7-sources-randomne...
For the price GP mentioned there's a dozen vetted opensource commercial options in the bottom half of that range.
Ironically, this is the same setup as the lavalamps, but without having to pay for the lava lamps.
Testing for randomness is impossible in the YES/NO sense, so the best we have is statistical test batteries like NIST's 800-22, DieHarder and TestU01.
I own a Truerng and a Onerng, both are under $50. They performed better on Dieharder than my computer's Intel RNG. Not by a huge margin, but still. All 3 passed the minimum requirements of course.
I guess we're still well within budget.
Hardware or /dev/urandom (or Windows equivalent) and downstream library calls - many bits, high data rate
So lava lamps produce higher entropy than a potato everything else being equal.
They should give credit to LavaRand classic, invented at SGI by Bob Mende & Sanjeev Sisodiya (Mende's passing still feels recent to me https://www.legacy.com/obituaries/dailyrecord/obituary.aspx?...) or its sequel LavaRnd (https://www.lavarand.org/news/lavadiff.html) invented by Landon Curt Noll and Simon Cooper.
[spoiler below]
https://twitter.com/ncis_cbs/status/1044751471927947264?lang...
From https://blog.cr.yp.to/20140205-entropy.html
how can anyone simultaneously believe that:
- we can't figure out how to deterministically expand one
256-bit secret into an endless stream of unpredictable
keys (this is what we need from urandom), but
- we _can_ figure out how to use a single key to safely
encrypt many messages (this is what we need from SSL,
PGP, etc.)?
I don't. Those lava lamps are cool looking, but that's about their only value. We don't need that many random bits.My guess is they have a couple of quantum HRNGs in those "Linux systems" they discuss that are actually doing the majority of the entropy.
Cool gimmick though.
https://www.phoronix.com/scan.php?page=news_item&px=Linux-Rd...
https://www.reddit.com/r/crypto/comments/h07u2q/rdrand_perfo...
Personally? Not at all, I do it for fun. On windows it's all you have because adding anything to the entropy pool BCryptGenRandom draws from is a no go, it was possible ten years ago, a simpler time. Now you have to do it yourself and xor different sources at the application layer if so concerned. On Linux it's trivial.
Cloudflare? Well, besides their obvious immediate needs, they are openly positioning themselves as an entropy provider for high security purposes, which requires good sources and throughput. What Intel or AMD is offering out of the box is not going to cut it by itself.
Not saying they're broken, they work fine for nearly all purposes, instead here positing that if your entire existence and everything you owned depended on it would you truly just use the inbuilt CPU RNG on your computer and call it day? It's a small amount of time to add additional sources and not lose your shirt/dignity.
The lava lamps aren't doing anything for Cloudflare's security. They're a marketing gimmick. A very good one! They got articles like this written! I'm not begrudging them the win! But this is not in fact how you engineer cryptography.
And yet you rely on one daily. Random oracles will likely be big business one day. I'm happy CF has put forward their posture on this. It's a good thing for the internets.
> nor is "good sources and throughput"
So you can provide entropy with high quality guarantees at 10GB/s? Sign me up mate. What's your price?
> I've been cagey about writing about this but this thread is now old
Who the fuck cares? Is this thread about actual discussion of the issue at hand or petty HN posturing? Couldn't care less what influencers and randoms here think. Simply stating thoughts and experiences.
> there is a misconception that running cryptography primitives somehow burns through entropy
Certainly agree, that's not what I meant though. A broken seed is nearly always exploitable in practice. It doesn't matter in the slightest how strong your primitives are when they are deterministic.
> The lava lamps aren't doing anything for Cloudflare's security. They're a marketing gimmick. A very good one!
Yeah, of course it's marketing, but with purpose, exposing devs to this stuff is worthwhile, means to an end and all that. XOR'ing sources is as cryptograhpically strong as the best source provided, why not do it if you have much at stake and 20 mins to spare.
well what if you show up with a white blanket and putit in front of the camera?
Really, the least-significant-bit noise from any camera chip, even pointed at nothing, fed through e.g. SHA-256, gives high-quality cryptographic random numbers at as high a rate as you are likely to want. (If you need better random numbers, you also have no need to read this.)
You can get similar quality from hashing the low bits of a mic input.
Hashing already-connected noise is actually better than resistor or diode noise, that is tricky to get right -- although feeding output of one of those through a good hash forgives a lot of bias.
But that's one whopping reservation, and even if, you could only predict exactly to the extent fluid dynamics exactly models interacting particle physics involving mind-boggling numbers (for the scales of interest).
Also, I have no background solving complex fluid dynamics problems, but my understanding is that the differential equations involved generally have to be solved with iterated numerical approximations (if anyone here knows more certainly, please do chime in). In the short term that's probably one of the smaller problems, but it is at least somewhat connected to why we don't get get highly reliable 3-week weather forecasts, and possibly never will.