2,242 karma · joined October 17, 2012
Website: https://mrosenberg.pub Github: https://github.com/rozbb Keybase: https://keybase.io/mrosenberg Email: michael (@) mrosenberg (.) pub
[ my public key: https://keybase.io/mrosenberg; my proof: https://keybase.io/mrosenberg/sigs/dR6U3ijr9MYZyBe0ueW6L90pU8Adb817jaeWietnOH4 ]
This was a great read, if you want a mathematical take on it, and some generalization too. https://arxiv.org/abs/math/0305282v1
WaveNet is 2018 tech though. I'm curious why that hasn't gotten cheaper.
https://www.science.org/content/article/contrary-popular-bel...
> Afaik nobody is doing this right now, easy win, no Predator drones required
What? This doesn't work for like 3 reasons. I'm not standing up for Yudkowsky here, but this response isn't very good.
The answer, I believe, is we have no way of doing that so far. The closest thing that exists is "multiparty" or "distributed" generation of an RSA modulus. Roughly, in the two party case of Alice and Bob, this means Alice picks some pair of numbers (P1, Q1) and Bob similarly picks some (P2, Q2). Then, Alice and Bob engage in some secure multiparty computation protocol whereby they obliviously a) check P1+P2 and Q1+Q2 are prime, and b) if so, output N=(P1+P2)(Q1+Q2) to both Alice and Bob.
At the end of the protocol (after repeating enough times that it succeeds), both parties have derived an N whose factorization they don't know.
I don't know much about this area of study, but searching multiparty RSA modulus generation should bring up relevant papers.
https://www.nytimes.com/2020/01/23/nyregion/nyc-cashless-ban...
The only solution to the replay problem is to have the poor-entropy machine keep a strikelist of all the messages (or hashes thereof) it has ever received from the entropy service. Thus, when receiving a new message, it can make sure it's not a replay. Of course, this means that you've turned a stateless protocol into a stateful one, and require non-volatile storage on the device for a potentially long period of time.
As far as I know, nobody actually does this.
Thought experiment: Suppose you had a computer that didn't have a good entropy source. You need this computer to have good entropy because it needs to connect to some service, and the connection needs to be cryptographically secured and resilient to replay attacks (ie attacks where an adversary, not necessarily the service, sends an old message in response to a fresh request). Suppose further that you had a separate service that exposes a camera feed of some lava lamps—perfect for fixing your entropy problem. How do you suppose you will connect to that camera feed?
[0] https://www.cvedetails.com/vulnerability-list.php?vendor_id=...