Re: SPES (my new encryption) one of its kind
- From: "giorgio.tani" <giorgio.tani@xxxxxxxx>
- Date: 18 May 2006 08:54:34 -0700
although method like this may lead to objections being raised ,howeverHum, it seem that idea is quite popular, I was thinking something
unless the hacker knows that you are now collecting data for randomness
he will not get the pages
similar posting on sci.crypt.random-numbers some years ago!
However it has some shorcomings: it's easy to track or tamper, is not
viable when low speed connection or no connection at all is available.
Moreover the entire size of human data (not all accessible!) is
exteemed to be in the order of magnitude of exabyte in size
(http://en.wikipedia.org/wiki/Exabyte), to give an idea of what means,
16 exabyte are 8*2^64 bits, about in the order of bits * 10^20
If you think to a 64 bit cypher or prng, the keyspace (longer
considered obsolete) is sized 64 bit * 2^64 keys thats 16 exabyte
too...
That doesn't mean a lot by itself, an exabyte of zeroes is not suitable
to be sampled for randomness, while instead you may find an exabyte of
pure random data.
However, that should spot that you should not rely on the quantity of
the data sampled, but rather on the method and on the quality of the
sample.
i.e. a mouse movement, providing it's not intercepted by malicious
programs, contain some pits of randomness, the entire wikipedia dump,
that the attacker may download as well if only know your sampling
method will not bring a single bit of randomness, since the attacker
got it... if sampling the wikipedaia dump is one out of two mathods,
the attacker has 50% chance of chosing the right method and recover the
whole GB sized "randomness" pool, and so on (so the randomness is in
how the method coiche is seeded, it's plainly moving the problem to
another level, and, being realistic, posing some tecnical issue to the
attacker... and many to the legitimate receiver too).
.
- References:
- SPES (my new encryption) one of its kind
- From: doctoresam
- Re: SPES (my new encryption) one of its kind
- From: giorgio.tani
- Re: SPES (my new encryption) one of its kind
- From: doctoresam@xxxxxxxxx
- Re: SPES (my new encryption) one of its kind
- From: giorgio.tani
- Re: SPES (my new encryption) one of its kind
- From: doctoresam@xxxxxxxxx
- Re: SPES (my new encryption) one of its kind
- From: giorgio.tani
- Re: SPES (my new encryption) one of its kind
- From: doctoresam@xxxxxxxxx
- Re: SPES (my new encryption) one of its kind
- From: giorgio.tani
- Re: SPES (my new encryption) one of its kind
- From: doctoresam@xxxxxxxxx
- Re: SPES (my new encryption) one of its kind
- From: giorgio.tani
- Re: SPES (my new encryption) one of its kind
- From: doctoresam@xxxxxxxxx
- Re: SPES (my new encryption) one of its kind
- From: giorgio.tani
- Re: SPES (my new encryption) one of its kind
- From: doctoresam@xxxxxxxxx
- SPES (my new encryption) one of its kind
- Prev by Date: Re: SPES (my new encryption) one of its kind
- Next by Date: SHA-1 algorithm OID and its BER encoding
- Previous by thread: Re: SPES (my new encryption) one of its kind
- Next by thread: Re: Tor Security Discussion Thread
- Index(es):
Relevant Pages
|
|