LWN.net Logo

LCE: Don't play dice with random numbers

LCE: Don't play dice with random numbers

Posted Dec 4, 2012 15:46 UTC (Tue) by nix (subscriber, #2304)
In reply to: LCE: Don't play dice with random numbers by madhatter
Parent article: LCE: Don't play dice with random numbers

Likewise here. It's useful for its stated purpose, and its design has that nice polished, 'we thought of everything' feel to it. (It's also a disproof of Bruce's comment that all you need is a single diode junction and appropriate detector: you want two and a correlation detection algorithm of some kind, and probably a thermometer as well, to protect against both particular known attacks (e.g. heating the thing up) and unknown attacks against the physical device (which would be likely to affect both diodes in the Entropy Key, thus causing some degree of unexpected correlation between the two). Even then, unknown attacks that bias both diodes yet cause them to remain apparently uncorrelated but actually correlated will still slip through.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds