Re: High Quality Random sources, was: Re: SecuriKey

From: Mark Borgerding
Date: Sun Jan 11 2004 - 23:17:41 EST


Disregarding the debates of true vs. pseudo randomness, ( an argument best left to cypherpunks, philosophers, and quantum physicists ) -- let me repeat the question the original poster asked ...

Does anyone have any info about securikey? The "white papers" on their website are nothing but fluff.
It smells like snake oil to me -- probably just a thumbdrive with an authentication driver.

Unless it actually encrypts the hard disk, it can't provide much security.
The system can most likely still be booted from a floppy or cdrom.

-
Mark Borgerding


Stephen D. Williams wrote:

Impossible? I think not. Some "mechanical" devices do exhibit true random capability, especially when enhanced by algorithmic means.
To wit: http://www.lavarand.org/

Let me know if you can prove their methods don't provide a true "high quality" random source.

I'd like to see their code as a module with an automatic test to make sure that the random source is high quality. In this case, that would mean making sure that the cap was not off the camera.

sdw

tabris wrote:

...
I should also mention that the problem with 'generating' an OTP via any mechanical or algorithmic means is impossible as at best an OTP will only be pseudo-random, and therefore with identical inputs (assuming it is possible, which we can assume here for the sake of theory and security), the same OTP can be generated, thus breaking our assumption/necessity of non-deterministic output.

I'd say more but I'm on my way to work.
- --
tabris
- -
I do not know whether I was then a man dreaming I was a butterfly, or
whether I am now a butterfly dreaming I am a man.
-- Chuang-tzu
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFAAagR1U5ZaPMbKQcRAmo2AJ0Wc6xTLCd/swZYlEO6emktLhOtRgCfUUP5
OB4YFi6bh1yrVMzGIoN6XNs=
=O/uT
-----END PGP SIGNATURE-----

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/






-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/