Re: /dev/random: really secure?

From: David Feuer (David_Feuer@brown.edu)
Date: Mon Dec 18 2000 - 03:49:44 EST


At 09:21 AM 12/18/2000 +0100, Karel Kulhavy wrote:
> > There are hidden sources of entropy. One is clock skew between
> the keyboard
> > processor's clock, the keyboard controller's clock, and the CPU clock
> > generator's PLL. Another is data motion between the CPU cache and main
>
>In the RFC 1750, they write it is not recommended to rely on computer
>clocks to
>generate random. Isn't it this case?

This is the case, but the important thing that David Schwartz said is that
it does not rely on the time in a clock, but rather on the pretty much
completely random skew between several independent clocks. Any particular
oscillator will vary in speed semi-randomly, and if you compare multiple
clocks you can get pretty random numbers.

--
This message has been brought to you by the letter alpha and the number pi.
Open Source: Think locally; act globally.
David Feuer
David_Feuer@brown.edu

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Sat Dec 23 2000 - 21:00:21 EST