Fun fact, HN itself was "hacked" due to bad random once (https://news.ycombinator.com/item?id=639976).
Fun fact, HN itself was "hacked" due to bad random once (https://news.ycombinator.com/item?id=639976).
For example this has passed NIST SP800-22 and SP800-90B [1].
As far as I can tell, cloudflares DIY lamps/pendulums are not NIST certified.
[1] https://www.idquantique.com/random-number-generation/product...
Some would claim that CMVP, FIPS 140-3, Common Criteria stickers on a black box (HSM) is security theater.
They do, don't they? I think the Lavalamps, etc, are just _extra_ entropy. The more entropy you add (even if it's _not_ a certified or perfect random source) only improves the random number generator.
jk.
That makes them by definition worse than the OpenSSL version that leaked user keys on request. /s
Like all the COVID-prevention theatre: sitting in restaurants and only masking when you visit the toilet. Hand-washing often whilst in unventilated areas with no masks. That's all "COVID theatre" IMO, as it fails to actually prevent the thing ostensibly being tackled.
My favourite one FWIW was wiping down the seat padding in the gym where nobody was masked - I mean who came up with that??
A creative hardware source of legit randomness is not the same as security theatre, and arguably has some useful educational aspect - it's certainly a talking point!
COVID aside, isn't wiping down gym equipment after use just good sanitary practice? I don't want to slide in on someone else's greasy residue.
It is quite a leap to say "timestamp-based seeds are insecure, let's upgrade to lava lamps".
The digit chance is easy:
For a single digit to appear one needs 1/3 * 1/10 = 1/30.
For a single letter to appear one needs 1/3 * 1/26 = 1/78.
But the bits of entropy throw me off. 26 + 26 + 10 = 62, which is 2^5.954. But that is for a uniform distribution. The writer states that it actually is 2^5.826, or 1/~56.7. I don't get how they to that number.
Like you said, the probability of any digit appearing is 1/30, and there are 10 digits. The probability of a lower- or upper- case letter appearing is 1/78, and there are 26+26 = 52 letters.
Plugging that into the formula for Shannon entropy, we get this:
- 10 * (1/30) * log_2(1/30) - 52 * (1/78) * log_2(1/78) =~ 5.826
Yes it is much more cool to look at than a zener diode, but it is still a source of physical entropy. And one could argue that a whole bunch of chaotic pendulums are more resilient to failure than a single diode.