Safer entropy accumulation in Linux 5.18's RNG
twitter.com
twitter.com
https://git.kernel.org/pub/scm/linux/kernel/git/crng/random....
It's quite detailed.
The nutshell of this is that `mix_pool_bytes` (we'll call it M), the LFSR mixing function in the core of the LRNG, has been replaced with Blake2. The M function is slow doesn't adequately recover security if the state is compromised. This is a well-known problem, but one no longer accepted in new designs as CSPRNGs are increasingly formalized.
The new LRNG is much simpler (a lot of it is simply calls to Blake2 now), easier to reason about, and fast.
But this doesn't change the chacha20-based CSPRNG that actually ends up being the output of /dev/urandom?
But am i correct in saying this entropy mixing eventually leads to some seed data that seeds the chacha20-based CSPRNG?
Uhh ... was the kernel not already using a cryptographically secure hash function to mix new randomness in?!
I haven't gone through the entire paper yet. Any idea what sort of threat model involves compromise of the PRNG state but not the entropy pool being used to refresh it? Assuming cryptographically secure functions it seems like being able to determine the internal state would necessitate low level access to the system so you could directly read it.
> If an attacker has access to the system to such a degree that he can learn the internal state of the RNG, arguably there are other lower hanging vulnerabilities -- side-channel, infoleak, or otherwise -- that might have higher priority.
I think this probably matches most people's intuitions.
> On the other hand, seed files are frequently used on systems that have a hard time generating much entropy on their own, and these seed files, being files, often leak or are duplicated and distributed accidentally, or are even seeded over the Internet intentionally, where their contents might be recorded or tampered with. Seen this way, an otherwise quasi-implausible vulnerability is a bit more practical than initially thought.
This is a reiteration of "unpredictable initial seeding is hard."