Harnessing chaos in Cloudflare offices
blog.cloudflare.com
blog.cloudflare.com
I really enjoyed how this article covered a variety of different "hacker-spirit" things; real-world entropy into "digital-world" meaningful use cases, plus a whole extra "one more thing" timelock encryption example at the end.
As someone who uses Cloudflare Workers / Pages heavily these days whenever I can, it's quite fun to see both "how the sausage is made" as well as the culture (playfulness?) behind it. Kinda makes me want to go visit the Austin office since I'm local.
Kudos and thanks to the Cloudflare team for writing stuff like this up! One of the more enjoyable tech pieces I've read in the past couple of weeks, and I learned multiple things along the way.
https://en.wikipedia.org/wiki/Johnson%E2%80%93Nyquist_noise
spending so much time devising ways to mitigate or remove noise, it becomes difficult to think of it as a 'feature'...
For a practical application: as you can imagine, there are certain crimes where it really makes a difference if an image is just on a phone, or if it was verifiably taken by that phone. Possession-of vs. Production-of...
Take printers for example, with some known to print a signature. Clearly they can still print a sheet a solid colour (or a number 0-100, or something character or whatever) at random (given some random source & control for doing so I mean) despite the device being identifiable.
A substantial portion of the "noise" from a CCD is definitely not random.
A lot of the camera is just functionality to make actual pictures better that don't apply here. Eg you don't need to control exposure with shutter speed if it's in a black box.
Having a whole camera might even be counterproductive. Eg actuating the shutter is predictable, so it might reduce entropy if actuating the shutter creates a signal that shows up in the randomness.
Or maybe they just mean pro quality cameras, but I'm not sure why you'd want a whole camera instead of just the sensor. Reasons are not readily apparent, and I don't expect anyone to be immediately ready to correct me on trade secrets.
Noise reduction algorithms are going to affect the entropy if you can't get raw values, and the level of AI crap in cell phone cameras makes it even worse these days.
Random.org generates random numbers by collecting static hiss from untuned radios around the world, selling them if they are required in bulk.
The use of a group of trusted randomness generators, a majority of whom would have to collude in order to trick a consumer into thinking an input was random when it was actually staged, offers genuine functionality that cannot be dismissed as "just marketing".
The Linux random number generator did used to have a notion of entropy depletion, but that is no longer the case (at least for x86-64 systems: https://wiki.archlinux.org/title/Random_number_generation).
On older systems that have a notion of entropy depletion, you would eventually deplete the entropy counter and /dev/random would start blocking if you aren't feeding new entropy into the system.
https://lwn.net/Articles/961510/
(CPUs may have hrngs but there are certain observations on their behaviour that create concern)
That person's point was that it's impossible to know for sure if entropy collection is broken. In practice it isn't an issue as you can make the false positive rate very small even if it can never be 0.
So… I think it’s relying on a cryptographically secure hashing function to become random enough to rely on, correct?
https://www.forbes.com/sites/kevinknudson/2015/07/29/pendulu...
And
Https://physicsworld.com/a/the-secret-of-the-synchronized-pendulums/
Still, probably plenty of entropy. But a weird choice if you know the context?
How hard is it to prove true randomness?
My guess is that it is either incredibly difficult or impossible. Or at least one would need an enormous number of samples to start the analysis.
What you can do instead is run code audits, analyze the theoretical basis of the entropy source, and test large amounts of data for its statistical properties. That can get you to near certainty, but it's still empirical.
Do you offer randomness as a service? People contact your API to retrieve random data? or do you sell software / hardware to create random data?
Is it actually practically/meaningfully more "Secure" than the standard PseudoRandom approaches that everyone relies on today?
Short of "Nation States sharing secrets of alien technology", is this actually significant to any customer's practical applications?
Right, so they've gone to all this effort to generate input as close as possible to random, then they undermine it by opening it up to the public?
Would be interesting to see what the camera placement is like and if that's at least secure, otherwise someone's is just going to stick a still picture on the end of it...
If you're going to go to all this effort to create randomness, at least secure it from physical interference...
Sorry, I know I'm being a cynical here. This just feels like a marketing gimmick.
The reason these entropy sources are used is because there's no such thing as a perfectly random algorithm. If there's a way to remove the entropy from the system then the whole thing becomes pointless, and you may as well go back to using a pseudorandom algorithm. That's my point.
If you care this much about ensuring true randomness then I'd argue the security of the system should be a primary consideration – perhaps the primary consideration. If you can't guarantee that you're entropy source is random, then you can't be confident of the randomness of the system generally.
I'm not an expert on this though so if someone wants to explain why I'm wrong then please do so.
That being said, the randomness on the sensor alone would probably defeat that, but also you could just check to make sure the previous image and the current image don't have the same hash, which I suspect Cloudflare does just as a basic error check.
I'm assuming if you start screwing around with shit the security guards will show up and point guns at you...
Ha, which ones do you know of?
https://blog.cloudflare.com/lavarand-in-production-the-nitty...
Even if you managed to 100% compromise this source, there's still a pool of other sources involved.