True randomness
Posted Mar 31, 2012 15:25 UTC (Sat) by
man_ls (subscriber, #15091)
In reply to:
True randomness by alankila
Parent article:
Russell: Sources of Randomness for Userspace
While this all sounds appropriately cryptic,
dark and foreboding,
By the way, the foreboding part is not just theoretical. See precisely this week's
security QotW:
I believe that what the "top official" was referring to is attacks that focus on the implementation and bypass the encryption algorithm: side-channel attacks, attacks against the key generation systems (either exploiting bad random number generators or sloppy password creation habits) [...]
Guess who employs thousands of cryptographers precisely to study these vulnerabilities. If the NSA had found a vulnerability in /dev/urandom (or ten) they would probably not publish them. "No known attacks" in cryptography seems to be a meager consolation, but in RNGs it is doubly so.
(
Log in to post comments)