The Lava Lamps That Help Keep the Internet Secure (2017) [video]
youtube.com
youtube.com
It seems that they've pointed a camera at a wall of lava lamps, and the output video feed is fed into their randomness generator. I wonder how they account for the fact that: (A) Most of the video feed is constant, only the blobs in the lava lamps move (B) Lava lamps aren't actually all that random (C) The wall is visible from the street, and someone with nation-state-level surveillance technology could easily reconstruct what that camera is seeing.
They do feed it as a one source, but it’s basically for fun.
I imagine if you (e.g.) XOR the state of a strong PRNG with the timestamp from an atomic clock whenever your Geiger counter goes off, you'd have infinite true random.
There are literally thousands of academic papers written on the topic of un-biasing and “extracting entropy” from noise sources. Most are overly complex; if you want a practical but secure approach see Yarrow, Fortuna, or the Linux kernel entropy pool.
Secondly, non-cryptographic PRNGs leak their state from their outputs.
This is a solved problem. Many academic and engineering hours have been put into real solutions. Dear reader, please use a recognized secure scheme instead of the amateur ad-hoc approach recommended up-thread. It has no theoretic or engineering basis. Don’t roll your own crypto.
A secure hash function has the avalanche property that changing 1 bit in the input, has an independent 50% chance of flipping each bit in the output.
So you just need to ensure that you have enough entropy for your desired security level.
Anybody wanting to reconstruct what the camera is seeing would have to reconstruct it to the exact pixel values, including any noise. i.e. you would have to intercept the signal from the camera they are using, you couldn't just point another camera at the wall.
https://blog.cloudflare.com/lavarand-in-production-the-nitty...
Which answers all your questions. Tl;dr: the lava feed is only an additional entropy source, it's not like they generate keys directly from the video feed.
0. https://medium.com/vault12/how-to-get-true-randomness-from-y...
It goes on to belabor the issue of runs of zeroes from oversaturated pixels. Stirring the whole frame into your entropy pool, all the non-random bits simply fail to add any entropy; they are otherwise harmless, no-op bits. But every frame has more than enough entropy, so the only way it matters is that stirring in a string of zeroes consumes power without adding entropy. If it takes as much energy to filter out the zeroes as to stir them in, you have achieved nothing by filtering them.
https://www.rtl-sdr.com/rtl-sdr-as-a-hardware-random-number-...
Disclaimer: I participated in the development of this.
What does matter is whether you have the entropy you need when you need it. Your favorite radioactive source might not have that. At device power-on, you might need entropy before the camera or radio receiver is initialized. That is when you need to consider carefully where to get some entropy, and how much of it you need right then. Maybe you can arrange to have saved enough over from when you were last powered up.
A blank wall would work equally well. The actual source of randomness is noise in the individual pixels affecting the least significant bits of the analog samples. Every camera supplies way more than enough entropy for any conceivable use.