|
|
Subscribe / Log in / New account

LCE: Don't play dice with random numbers

LCE: Don't play dice with random numbers

Posted Dec 3, 2012 18:32 UTC (Mon) by madhatter (subscriber, #4665)
In reply to: LCE: Don't play dice with random numbers by Kaejox
Parent article: LCE: Don't play dice with random numbers

I have no idea if you're involved with Simtec, but I'll add my 2p-worth with the disclaimer that I'm not, I'm just a happy customer who once bought one of the Entropy Keys at full price. I like it. They're honest about what's inside the device, which is itself an elegant thing, and it keeps my poor, previously-entropy-starved colocated server full of nice chewy randomness.


to post comments

LCE: Don't play dice with random numbers

Posted Dec 4, 2012 15:46 UTC (Tue) by nix (subscriber, #2304) [Link]

Likewise here. It's useful for its stated purpose, and its design has that nice polished, 'we thought of everything' feel to it. (It's also a disproof of Bruce's comment that all you need is a single diode junction and appropriate detector: you want two and a correlation detection algorithm of some kind, and probably a thermometer as well, to protect against both particular known attacks (e.g. heating the thing up) and unknown attacks against the physical device (which would be likely to affect both diodes in the Entropy Key, thus causing some degree of unexpected correlation between the two). Even then, unknown attacks that bias both diodes yet cause them to remain apparently uncorrelated but actually correlated will still slip through.


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds