Re: [RFC][PATCH 0/6] /dev/random - a new approach

From: Sandy Harris
Date: Fri Apr 22 2016 - 09:09:55 EST


On Thu, Apr 21, 2016 at 10:51 PM, Theodore Ts'o <tytso@xxxxxxx> wrote:

> I still have a massive problem with the claims that the "Jitter" RNG
> provides any amount of entropy. Just because you and I might not be
> able to analyze it doesn't mean that somebody else couldn't. After
> all, DUAL-EC DRNG was very complicated and hard to analyze. So would
> be something like
>
> AES(NSA_KEY, COUNTER++)
>
> Very hard to analyze indeed. Shall we run statistical tests? They'll
> pass with flying colors.
>
> Secure? Not so much.
>
> - Ted

Jitter, havege and my maxwell(8) all claim to get entropy from
variations in timing of simple calculations, and the docs for
all three give arguments that there really is some entropy
there.

Some of those arguments are quite strong. Mine are in
the PDF at:
https://github.com/sandy-harris/maxwell

I find any of those plausible as an external RNG feeding
random(4), though a hardware RNG or Turbid is preferable.