True hardware random number generator for $50
tindie.com
tindie.com
Though exploring that tangent a little, I wonder if there is a any sort of study on flags\countries and their association with quality (specifically engineering\tech). Off the top of my head I'd guess people associate places like Sweden, Germany, Switzerland, Austria - I'm not sure why.
A pirate flag might work.
How so? I usually think of Germany as being pretty good technologically.
Any flag is a bit weird.
This company is going to lose sales for something as trivial as a flag on an easily removable sticker.
I'm sometimes surprised to see HN - which freaking loves AB testing the colour of signup buttons - is resistant to people saying "I dislike this minor detail".
There should be a way for HN users to point out things they dislike about a product - politely, constructively, without undue negativity, and without derailing the thread with off-topic noodling about the website (unless the website is the product).
Really? I can't imagine it'll HURT them. If they're proud of having it made in the US, who does that bother enough to say "man such a great product, but nope, not gonna buy it". I'd say it might have a marginal effect the other way, for people who like to buy US-made products, and almost no effect the other way.
You can get a $10 RTL-SDR [1] dongle that happily churns out over 2MSp/s and feed random radio noise to your entropy pool using rtl_entropy [2].
Also what's up with the flag, 'murica?
"If you're serious about the cryptographic security of your entropy source, you should probably short, or put a 50 Ohm load on the antenna port, and put the whole assembly in a shielded box. Then you're getting entropy from the thermal noise of the amplifiers which is much harder to interfere with than atmospheric radio."
But where do you find $10 dongles? I've found just NooElec NESDR XTR for $50? Edit: OK, there are cheaper dongles with RTL2832U, just not with E4000
This complaint is akin to people who complain "a $700 iPhone only has $150 of parts." It might be true, but it ignores the entire development cost, value add, and ease of use relative to buying a box of bolts and building an iPhone (or in this case a RND source).
Their price is very reasonable, and your $10 alternative is not a realistic alternative.
The case of the TrueRNG looks identical to the Entropy Key, but for all I know that could just be a common part.
Huh? Some PRNGs sure, but I don't really know what this is trying to prove. The output of any decent stream cipher will appear just as random.
Shameless self-insert: https://github.com/joshleaves/node-qrand
(bad due to visible patterns, compared to the shown picture for their hardware generator: http://ubld.it/wp-content/uploads/2014/02/random_bitmap.png )
Curiously, the shop shows sales data:
376 orders / 22 reviews
Since Mar 04, 2014
(as of about 14h WEST, 2015.05.22, let's see if it budges ;-)http://csrc.nist.gov/groups/ST/toolkit/rng/batteries_stats_t...
http://spectrum.ieee.org/computing/hardware/behind-intels-ne...
The problem is that it is a black box. Intel has added the ability to seed the generator (rdseed), but it does not really reduce the issue of trust.
Also the rdseed instruction does not allow you to seed the generator but instead allows you to generate seeds for other (pseudo random) generators.
https://software.intel.com/en-us/blogs/2012/11/17/the-differ...
http://sharps.org/wp-content/uploads/BECKER-CHES.pdf
If RDSEED doesn't run through the hash, would that give you enough of a window into the PRNG's internal state to be able to catch that attack? It sounds promising but it looks like RDSEED came out in 2012, so that would predate the paper...
So is this one... it's also closed-source hardware.
Some people were against it; others not so much.
http://en.wikipedia.org/wiki/RdRand
http://arstechnica.com/security/2013/12/we-cannot-trust-inte...
By doing that, all the security of the system is dependent on Intel's RNG. There's not really any downside to mixing this in with other sources of entropy, even if RDRAND were backdoored, rdrand XOR other_entropy should be equally secure as other_entropy.
If your last random source comes from an attacker who can read your state, then they can manipulate your state freely (XOR) or partially (any PRF), which could lead to trouble. Source: http://blog.cr.yp.to/20140205-entropy.html
Combining with a proper PRF limits the damage a bit compared to plain XOR, which is why Linux's /dev/random was changed to feed in RDSEED/RDRAND like any other entropy source.
On the other hand, there's the school of thought which says: if the CPU you're running on has been trojaned in hardware, you're probably buggered no matter what!
See here for a simpler explanation of building a random sequence generator using avalanche effect (sort of the precursor to this device I'd guess): http://holdenc.altervista.org/avalanche/
b) How do you verify that it's really random and not a CSPRNG with a key known to the NSA?
The site of the producers, though:
Looks like somebody who actually honestly likes to make his own hardware, and not only RNGs.
Maryland's economy takes advantage of the close location of the center of government in Washington, D.C. and emphasizes technical and administrative tasks for the defense/aerospace industry and bio-research laboratories, as well as staffing of satellite government headquarters in the suburban or exurban Baltimore/Washington area. Ft. Meade serves as the headquarters of the Defense Information Systems Agency, United States Cyber Command, and the National Security Agency/Central Security Service. In addition, a number of educational and medical research institutions are located in the state. In fact, the various components of The Johns Hopkins University and its medical research facilities are now the largest single employer in the Baltimore area. Altogether, white collar technical and administrative workers comprise 25 percent of Maryland's labor force, attributable in part to nearby Maryland being a part of the Washington Metro Area where the federal government office employment is relatively high.
I'm not suggesting they are the only country in that situation, nor that there is any sure-fire way to make sure you aren't hamstrung.
But I think it is a good rule of thumb to not rely on US crypto.
http://www.atarimagazines.com/compute/issue72/random_numbers...
Is there a way to measure how often this happens and what kind of improvements would be expected after buying a hardware RNG?
http://www.amazon.com/TrueRNG-Hardware-Random-Number-Generat...