Re: strengthening /dev/urandom

From: Tom St Denis (tomstdenis_at_iahu.ca)
Date: 08/20/04


Date: Thu, 19 Aug 2004 22:42:21 GMT

Guy Macon <http://www.guymacon.com> wrote:

>
> Jean-Luc Cooke <jlcooke@engsoc.org> says...
>
>>Prove us wrong. cite 1 example of a good entropy estimator. Academic
>>papers only. I downright double-dog dare you.
>
> I estimate that a series of fair coin flips is between 0.5 and 1.0
> bits of entropy per flip, and yes, I can find many, many academic
> papers that make estimates of the entropy of coin flips that have
> ranges that are entirely within my estimated range.
>
> The point being that it is easy to make a good entropy estimator if
> you understand the physics of your entropy source, and that you have

Our point is what if I swap your coin with a weighted one [this argument
works better with a die]?

Tom



Relevant Pages

  • Re: strengthening /dev/urandom
    ... The entropy estimations are USELESS they don't ... the entropy estimator is not an end in itself. ... ]that computer without noticing any bias. ... anywhere which looks at all like "yes this is random data". ...
    (sci.crypt)
  • Re: [PATCH 7/14] random: Remove SA_SAMPLE_RANDOM from network drivers
    ... add_network_randomness call in some central location in the network ... mix network samples into the entropy ... entropy accounting is conservative: ... that our entropy estimator gets it right. ...
    (Linux-Kernel)
  • Re: strengthening /dev/urandom
    ... >But if there's a state compromise and you don't wait enough for enough ... >new entropy to reach the output, then Fortuna is completely insecure. ... I think this analysis assumes /dev/random has a perfect entropy estimator. ...
    (sci.crypt)
  • Re: strengthening /dev/urandom
    ... without needing an entropy estimator for this purpose. ... > be some pool that has received 160 bits of real entropy since the leak ... If the real entropy generated in the system is 1 bit per ...
    (sci.crypt)
  • Re: RNG vs. PRNG vs. CRNG
    ... you have only 3.32 bits of entropy. ... compact sequence that has no redundancy. ... random letters (i.e., only characters A-Z), then ... flip a fair coin, ...
    (sci.crypt)